logo

Palo Alto Networks Expedition Tool Vulnerability Let Attackers Access Cleartext Passwords

ID: 9d9658dc-46c0-587b-8b06-a8b72ad56972

STIX ID: report--9d9658dc-46c0-587b-8b06-a8b72ad56972

Feed Name: GBHackers

Threat Score
60/100

Date Published: 2025-01-09

Date Updated: 2026-04-22

Author: Divya

...
...

Multiple vulnerabilities have been identified in Palo Alto Networks' Expedition migration tool—including a high-severity SQL injection (CVE-2025-0103, CVSS 7.8), other SQL/injection flaws, arbitrary file deletion, wildcard file enumeration, and command injection—that could expose cleartext passwords and device configurations; Palo Alto recommends updating to Expedition 1.2.101 or migrating away given the tool's EoL and the absence of reported active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.