EXPOSURES › CVE-2024-9463
CVE-2024-9463
HIGH ⌖ ON CISA KEV · EXPLOITEDPalo Alto Networks Expedition OS allows unauthenticated attackers to execute arbitrary root commands, exposing credentials and API keys.
This unauthenticated command injection vulnerability in Expedition OS enables attackers to run arbitrary OS commands as root, leading to the disclosure of cleartext passwords, usernames, and API keys for PAN-OS firewalls. DIB organizations must immediately patch or replace affected hardware to prevent unauthorized access to sensitive infrastructure and avoid compliance violations under FedRAMP and NIST 800-171.
Shame score — An unauthenticated RCE vulnerability in a critical security product that exposes cleartext credentials and API keys represents a severe, avoidable security failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Palo Alto Networks Expedition contains an OS command injection vulnerability that allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.
| PRODUCT | STATUS |
|---|---|
| GCS-HIGH Palo Alto Networks, Inc. |
Ready |
| Palo Alto Networks Government Cloud Services Palo Alto Networks, Inc. |
Authorized |