Palo Alto Networks Expedition Tool Vulnerability Let Attackers Access Cleartext Passwords
ID: 9d9658dc-46c0-587b-8b06-a8b72ad56972
STIX ID: report--9d9658dc-46c0-587b-8b06-a8b72ad56972
Feed Name: GBHackers
Threat Score
Multiple vulnerabilities have been identified in Palo Alto Networks' Expedition migration tool—including a high-severity SQL injection (CVE-2025-0103, CVSS 7.8), other SQL/injection flaws, arbitrary file deletion, wildcard file enumeration, and command injection—that could expose cleartext passwords and device configurations; Palo Alto recommends updating to Expedition 1.2.101 or migrating away given the tool's EoL and the absence of reported active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
