Expedition
CVE-2024-9465: Multiple Vulnerabilities in Expedition Lead to Exposure of Firewall Credentials
Multiple vulnerabilities in Palo Alto Networks Expedition allow an attacker to read Expedition database contents and arbitrary files, as well as write arbitrary files to temporary storage locations on the Expedition system.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Expedition 1 | 1.2.96 or later |
| Cloud NGFW | Not affected |
| Panorama | Not affected |
| PAN-OS | Not affected |
| Prisma Access | Not affected |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
Multiple vulnerabilities in Palo Alto Networks Expedition allow an attacker to read Expedition database contents and arbitrary files, as well as write arbitrary files to temporary storage locations on the Expedition system. Combined, these include information such as usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.
These issues do not affect the firewalls, Panorama, Prisma Access, or Cloud NGFW.
Workarounds
Ensure networks access to Expedition is restricted to authorized users, hosts, or networks.
If Expedition is not in active use, ensure that Expedition software is shut down.
For CVE-2024-9465, you can check for an indicator of compromise with the following command on an Expedition system (replace "root" with your username if you are using a different username):
mysql -uroot -p -D pandb -e "SELECT * FROM cronjobs;"
If you see any records returned, this indicates a potential compromise. Please note that if no records are returned, the system may still be compromised. This is only intended to indicate a potential compromise, rather than confirm a system has not been compromised.
There are no practical indicators of compromise for the remainder of the CVEs in this advisory.
Exploitation
Palo Alto Networks is aware of reports from CISA that there is evidence of active exploitation for CVE-2024-9463 and CVE-2024-9465. More information can be found at https://www.cisa.gov/news-events/alerts/2024/11/14/cisa-adds-two-known-exploited-vulnerabilities-catalog.
CISA lists this CVE as exploited in the wild since 14 Nov 2024.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.