CyberzSOC

Publication detail
← Back to advisories & guidance

2024-108: Palo Alto Critical Vulnerabilities ↗ source

October 11, 2024 CERT-EU Advisory

Summary

The vulnerabilities allow attackers to execute arbitrary commands, read or write files, and exploit SQL injection flaws. Successful exploitation could result in a full In the /var/apache/log/access.log file, anomalous calls to the following endpoints might indicate abuse of these vulnerabilities: It is recommended to upgrade to Expedition 1.2.96 or later to mitigate these vulnerabilities. The access and exposure to Expedition should also be limited.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-9463 9.9 Critical Palo Alto Networks Expedition Palo Alto Networks Expedition contains an OS command injection vulnerability that allows an unauthenticated attacker to run arbitrary OS commands as …
CVE-2024-9464 9.3 Critical Palo Alto Networks Expedition An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Exped…
CVE-2024-9465 9.2 Critical Palo Alto Networks Expedition Palo Alto Networks Expedition contains a SQL injection vulnerability that allows an unauthenticated attacker to reveal Expedition database contents, …
CVE-2024-9466 8.2 High Palo Alto Networks Expedition A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usern…
CVE-2024-9467 7.0 High Palo Alto Networks Expedition A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expeditio…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.