Multiple Vulnerabilities in Palo Alto Network’s Expedition Could Allow for Arbitrary Code Execution
ID: 94ca363f-44f7-50f0-b111-ab52a61e7d88
STIX ID: report--94ca363f-44f7-50f0-b111-ab52a61e7d88
Feed Name: CISecurity.org Advisories
Multiple high-severity vulnerabilities were discovered in Palo Alto Networks Expedition, including unauthenticated OS command injection and SQL injection that can lead to root-level code execution and disclosure of usernames, cleartext passwords, device configurations, and PAN-OS API keys; additional lower-severity issues include cleartext storage of credentials and reflected XSS. Successful exploitation could allow attackers to install programs, view/change/delete data, and potentially compromise managed firewalls and their API access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
