CVE-2024-5910
Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.
- Affected products
- Palo Alto Networks Expedition
- Paloaltonetworks Expedition
- < 1.2.92
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 91.8% (100th percentile)
- Weakness
- CWE-306
- NVD status
- Analyzed
- Published
- 2024-07-10
- Attack patterns
- CAPEC-115
Fix
This issue is fixed in Expedition 1.2.92 and all later versions.
Workaround
Ensure networks access to Expedition is restricted to authorized users, hosts, or networks.
CVE-2024-5910 at NVD
8 known exploits for CVE-2024-5910
Proof-of-concept code and exploit modules indexed by Sploitus
π Palo Alto Networks PAN-OS 11.2 PHP Code Injection
π Palo Alto Networks Expedition 1.2.90.1 Privilege Escalation
Palo Alto Networks Expedition 1.2.90.1 - Admin Account Takeover
Palo Alto Expedition 1.2.91 Remote Code Execution Exploit
Palo Alto Expedition 1.2.91 Remote Code Execution
Palo Alto Expedition 1.2.91 Remote Code Execution
Palo Alto Expedition Remote Code Execution (CVE-2024-5910 and CVE-2024-9464)
Exploit for OS Command Injection in Paloaltonetworks Expedition