logo

Multiple Vulnerabilities in Palo Alto Network’s Expedition Could Allow for Arbitrary Code Execution

ID: 94ca363f-44f7-50f0-b111-ab52a61e7d88

STIX ID: report--94ca363f-44f7-50f0-b111-ab52a61e7d88

Feed Name: CISecurity.org Advisories

Threat Score
88/100

Date Published: 2024-10-14

Date Updated: 2026-04-27

...
...

Multiple high-severity vulnerabilities were discovered in Palo Alto Networks Expedition, including unauthenticated OS command injection and SQL injection that can lead to root-level code execution and disclosure of usernames, cleartext passwords, device configurations, and PAN-OS API keys; additional lower-severity issues include cleartext storage of credentials and reflected XSS. Successful exploitation could allow attackers to install programs, view/change/delete data, and potentially compromise managed firewalls and their API access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.