Palo Alto Expedition: From N-Day to Full Compromise
ID: 5b4d0b8d-870e-5206-a7c7-e6ab4a62ac6a
STIX ID: report--5b4d0b8d-870e-5206-a7c7-e6ab4a62ac6a
Feed Name: Security Boulevard
This report details discovery and exploitation of multiple vulnerabilities in Palo Alto Networks Expedition that allow attackers to reset admin credentials, gain remote code execution via an authenticated command-injection in CronJobs.php, perform unauthenticated SQL injection to exfiltrate user and device data, and recover cleartext credentials written to logs; proofs-of-concept, post-exploitation exfiltration steps, IOCs, exposure counts (~23 internet-facing servers), and a disclosure timeline are included.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
