Skip to content
COOEY

EXPOSURES › CVE-2024-9463

CVE-2024-9463

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-11-14 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-9463 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatcheddata-breach

Palo Alto Networks Expedition OS allows unauthenticated attackers to execute arbitrary root commands, exposing credentials and API keys.

This unauthenticated command injection vulnerability in Expedition OS enables attackers to run arbitrary OS commands as root, leading to the disclosure of cleartext passwords, usernames, and API keys for PAN-OS firewalls. DIB organizations must immediately patch or replace affected hardware to prevent unauthorized access to sensitive infrastructure and avoid compliance violations under FedRAMP and NIST 800-171.

Shame score — An unauthenticated RCE vulnerability in a critical security product that exposes cleartext credentials and API keys represents a severe, avoidable security failure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Palo Alto Networks Expedition contains an OS command injection vulnerability that allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
GCS-HIGH
Palo Alto Networks, Inc.
Ready
Palo Alto Networks Government Cloud Services
Palo Alto Networks, Inc.
Authorized