CISA warns of more Palo Alto Networks bugs exploited in attacks

Share:

CISA warned today that two more critical security vulnerabilities in Palo Alto Networks’ Expedition migration tool are now actively exploited in the wild.

Attackers can use the two unauthenticated command injection (CVE-2024-9463) and SQL injection (CVE-2024-9465) vulnerabilities to hack into unpatched systems running the company’s Expedition migration tool, which helps migrate configurations from Checkpoint, Cisco, and other supported vendors.

While CVE-2024-9463 allows attackers to run arbitrary OS commands as root, exposing usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls, the second flaw can be exploited to access Expedition database contents (including password hashes, usernames, device configurations, and device API keys) and create or read arbitrary files on vulnerable systems.

Palo Alto Networks is shipping security updates addressing these issues in Expedition 1.2.96 and later. The company advises admins who can’t immediately update the software to restrict Expedition network access to authorized users, hosts, or networks.

“Multiple vulnerabilities in Palo Alto Networks Expedition allow an attacker to read Expedition database contents and arbitrary files, as well as write arbitrary files to temporary storage locations on the Expedition system,” Palo Alto Networks added in a security advisory published in early October that still needs to be updated to warn customers that attackers are exploiting these vulnerabilities in the wild.

“Combined, these include information such as usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.”

“All Expedition usernames, passwords, and API keys should be rotated after upgrading to the fixed version of Expedition. All firewall usernames, passwords, and API keys processed by Expedition should be rotated after updating,” it added, saying that these security flaws do not affect its firewall, Panorama, Prisma Access, and Cloud NGFW products.

Federal agencies ordered to patch within three weeks

On Thursday, CISA added the two vulnerabilities to its Known Exploited Vulnerabilities Catalog, ordering federal agencies to patch Palo Alto Networks Expedition servers on their networks within three weeks, by December 5, as required by the binding operational directive (BOD 22-01).

One week ago, the cybersecurity agency warned of another Expedition security flaw—a critical missing authentication vulnerability (CVE-2024-5910) patched in July that can let threat actors reset application admin credentials—actively abused in attacks.

Even though CISA has yet to provide more information on these ongoing attacks, proof-of-concept exploit code released by Horizon3.ai vulnerability researcher Zach Hanley last month can help chain CVE-2024-5910 with another command injection vulnerability (CVE-2024-9464) patched in October to gain “unauthenticated” arbitrary command execution on vulnerable and Internet-exposed Expedition servers.

CVE-2024-9464 can be chained with other Expedition flaws (also addressed last month) to take over firewall admin accounts and hijack unpatched PAN-OS firewalls.

Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:03 pm, May 9, 2025
weather icon 12°C
L: 11° | H: 13°
clear sky
Humidity: 62 %
Pressure: 1021 mb
Wind: 10 mph ENE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 9%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:17 am
Sunset: 8:35 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
11° | 13°°C 0 mm 0% 11 mph 79 % 1020 mb 0 mm/h
Sun May 11 10:00 pm
weather icon
11° | 22°°C 0.66 mm 66% 11 mph 80 % 1015 mb 0 mm/h
Mon May 12 10:00 pm
weather icon
13° | 21°°C 0.38 mm 38% 14 mph 91 % 1014 mb 0 mm/h
Tue May 13 10:00 pm
weather icon
13° | 20°°C 1 mm 100% 10 mph 83 % 1020 mb 0 mm/h
Wed May 14 10:00 pm
weather icon
10° | 21°°C 0 mm 0% 12 mph 76 % 1025 mb 0 mm/h
Tomorrow 1:00 am
weather icon
11° | 12°°C 0 mm 0% 6 mph 66 % 1020 mb 0 mm/h
Tomorrow 4:00 am
weather icon
10° | 11°°C 0 mm 0% 4 mph 79 % 1020 mb 0 mm/h
Tomorrow 7:00 am
weather icon
11° | 11°°C 0 mm 0% 6 mph 76 % 1020 mb 0 mm/h
Tomorrow 10:00 am
weather icon
16° | 16°°C 0 mm 0% 9 mph 40 % 1019 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
18° | 18°°C 0 mm 0% 11 mph 30 % 1018 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
20° | 20°°C 0 mm 0% 11 mph 34 % 1017 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
17° | 17°°C 0 mm 0% 10 mph 41 % 1016 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
13° | 13°°C 0 mm 0% 7 mph 66 % 1016 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,595.68
0.23%
Ethereum(ETH)
€2,078.88
7.34%
Tether(USDT)
€0.89
0.00%
XRP(XRP)
€2.09
2.17%
Solana(SOL)
€153.34
7.13%
USDC(USDC)
€0.89
0.00%
Dogecoin(DOGE)
€0.182281
6.27%
Shiba Inu(SHIB)
€0.000013
6.47%
Pepe(PEPE)
€0.000011
10.73%
Peanut the Squirrel(PNUT)
€0.354996
87.35%
Scroll to Top