Threat intelligence report · CISA KEV

CVE-2024-9463: Palo Alto Networks Expedition OS Command Injection Vulnerability

Palo Alto Networks Expedition contains an OS command injection vulnerability that allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

· high severity · unattributed attribution

Evidence and provenance

Original source
CISA KEV report ↗
Published
2024-11-14T00:00:00Z
Confidence basis
No actor match
Record ID
01be60c2e2e4cbeda4ee

Vulnerabilities

CVE-2024-9463

Use and citation

Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.