Expedition

CVE-2024-9463: Multiple Vulnerabilities in Expedition Lead to Exposure of Firewall Credentials

Multiple vulnerabilities in Palo Alto Networks Expedition allow an attacker to read Expedition database contents and arbitrary files, as well as write arbitrary files to temporary storage locations on the Expedition system.

Published

ExploitedYes, in CISA KEVAdded 14 Nov 2024
Ransomware useNot reportedPer CISA
SeverityCRITICALCVSS 4.0 9.9
EPSS99%Chance of exploitation in 30 days
Public exploitNot tracked
FixAvailable

Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.

Affected and fixed versions

Product / branchFixed in
Expedition 11.2.96 or later
Cloud NGFWNot affected
PanoramaNot affected
PAN-OSNot affected
Prisma AccessNot affected

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

Multiple vulnerabilities in Palo Alto Networks Expedition allow an attacker to read Expedition database contents and arbitrary files, as well as write arbitrary files to temporary storage locations on the Expedition system. Combined, these include information such as usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

These issues do not affect the firewalls, Panorama, Prisma Access, or Cloud NGFW.

Workarounds

Ensure networks access to Expedition is restricted to authorized users, hosts, or networks.

If Expedition is not in active use, ensure that Expedition software is shut down.

For CVE-2024-9465, you can check for an indicator of compromise with the following command on an Expedition system (replace "root" with your username if you are using a different username):

mysql -uroot -p -D pandb -e "SELECT * FROM cronjobs;"

If you see any records returned, this indicates a potential compromise. Please note that if no records are returned, the system may still be compromised. This is only intended to indicate a potential compromise, rather than confirm a system has not been compromised.

There are no practical indicators of compromise for the remainder of the CVEs in this advisory.

Exploitation

Palo Alto Networks is aware of reports from CISA that there is evidence of active exploitation for CVE-2024-9463 and CVE-2024-9465. More information can be found at https://www.cisa.gov/news-events/alerts/2024/11/14/cisa-adds-two-known-exploited-vulnerabilities-catalog.

CISA lists this CVE as exploited in the wild since 14 Nov 2024.

Sources

KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.