FAIL › dossier
Expedition
PRODUCT· dossier confidence 20%
Palo Alto Networks' Expedition platform has recently been plagued by critical security vulnerabilities, including RCE and authentication bypass flaws, raising concerns about its overall security posture and potential impact on DIB/CMMC compliance. These issues necessitate immediate remediation and a review of development and testing processes. The repeated nature of these vulnerabilities suggests systemic weaknesses.
Palo Alto Networks Expedition has demonstrated significant vulnerabilities, evidenced by multiple high-severity Remote Code Execution (RCE) and authentication bypass flaws discovered in late 2024. These issues highlight weaknesses in the platform's security controls and potentially expose sensitive data and system access.
- CVE-2024-9465 (RCE): SQL injection allows database access
- CVE-2024-9463 (RCE): Arbitrary root command execution
- CVE-2024-5910 (High): Authentication bypass allows admin account seizure
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-11-14 | CVE-2024-9465 | high | Palo Alto Networks Expedition allows unauthenticated attackers to read database contents and execute arbitrary file operations via SQL injection. |
| 2024-11-14 | CVE-2024-9463 | high | Palo Alto Networks Expedition OS allows unauthenticated attackers to execute arbitrary root commands, exposing credentials and API keys. |
| 2024-11-07 | CVE-2024-5910 | high | Palo Alto Networks Expedition allows attackers to bypass authentication and seize admin accounts via network access. |
- ARC Raiders Expedition Requirements, Rewards & Resets · expcarry.com
- SUG Software Update Group Patch Deployments SCCM Report Using SQL Query ... · solatatech.com
- Anime Expeditions Updates — Patch Notes and Player Impact | Anime ... · animeexpeditions.org