Skip to content
COOEY

EXPOSURES › CVE-2024-5910

CVE-2024-5910

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-11-07 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-5910 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wilddefault-credsunpatched

Palo Alto Networks Expedition allows attackers to bypass authentication and seize admin accounts via network access.

This missing authentication flaw lets adversaries bypass login controls to hijack admin accounts and exfiltrate secrets, directly threatening FedRAMP vendor trust and DIB data integrity. Organizations must immediately patch Expedition deployments and audit exposed credentials.

Shame score — A critical authentication bypass in a widely deployed security product that enables full admin takeover without requiring a known exploit.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Palo Alto Networks Expedition contains a missing authentication vulnerability that allows an attacker with network access to takeover an Expedition admin account and potentially access configuration secrets, credentials, and other data.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
GCS-HIGH
Palo Alto Networks, Inc.
Ready
Palo Alto Networks Government Cloud Services
Palo Alto Networks, Inc.
Authorized