Critical Palo Alto Networks Expedition bug exploited (CVE-2024-5910)

Share:

A vulnerability (CVE-2024-5910) in Palo Alto Networks Expedition, a firewall configuration migration tool, is being exploited by attackers in the wild, the Cybersecurity and Infrastructure Security Agency (CISA) confirmed on Thursday.

About CVE-2024-5910

Unearthed and reported by Brian Hysell of Synopsys Cybersecurity Research Center (CyRC), CVE-2024-5910 stems from missing authentication for a critical function, which can lead to an Expedition admin account takeover for attackers with network access to the installation.

A security update fixing the vulnerability has been provided by Palo Alto Networks in July 2024. The company also advised those who couldn’t upgrade to make sure network access to their Expedition installation is restricted to authorized users, hosts, or networks.

The public disclosure of CVE-2024-5910 has spurred Horizon3.ai researchers to disclose (three months later) that the vulnerability could be exploited by sending a simple request to an exposed endpoint to reset the admin password:

CVE-2024-5910 exploited

Reseting the admin password (Source: Horizon3.ai)

They also decided to probe the tool for further weaknesses, and they found three:

  • CVE-2024-9464: An authenticated command injection
  • CVE-2024-9465: An unauthenticated SQL injection
  • CVE-2024-9466: Cleartext credentials in logs

Fixes for those vulnerabilities have been released in October 2024. But proof-of-concept exploit code for chaining the flaw with CVE-2024-9464 to achieve “unauthenticated” arbitrary command execution on vulnerable Expedition servers is publicly accessible.

What to do?

Whether CVE-2024-5910 is being exploited by itself or in conjunction with another vulnerability is unknown, because CISA didn’t share that information.

Palo Alto Networks has updated the advisory to say that they are “aware of reports from CISA that there is evidence of active exploitation for this CVE.”

If they haven’t already, users should upgrade their Expedition installation to a fixed version and make sure it is not exposed to the internet (as there is no reason for it).

Next, they should rotate all Expedition usernames, passwords, and API keys, as well as all firewall usernames, passwords, and API keys processed by Expedition.

Horizon3.ai’s Zach Hanley has previously explained how to check for indicators of compromise.

Zeljka Zorz

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:33 am, Jun 30, 2025
weather icon 19°C
L: 18° | H: 19°
overcast clouds
Humidity: 82 %
Pressure: 1021 mb
Wind: 8 mph ESE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:46 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
18° | 19°°C 0 mm 0% 9 mph 82 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
22° | 33°°C 0 mm 0% 10 mph 68 % 1016 mb 0 mm/h
Wed Jul 02 10:00 pm
weather icon
16° | 23°°C 0.65 mm 65% 10 mph 82 % 1021 mb 0 mm/h
Thu Jul 03 10:00 pm
weather icon
14° | 24°°C 0 mm 0% 10 mph 84 % 1026 mb 0 mm/h
Fri Jul 04 10:00 pm
weather icon
15° | 25°°C 0 mm 0% 13 mph 57 % 1027 mb 0 mm/h
Today 4:00 am
weather icon
18° | 19°°C 0 mm 0% 3 mph 82 % 1021 mb 0 mm/h
Today 7:00 am
weather icon
19° | 21°°C 0 mm 0% 4 mph 78 % 1021 mb 0 mm/h
Today 10:00 am
weather icon
24° | 26°°C 0 mm 0% 6 mph 60 % 1020 mb 0 mm/h
Today 1:00 pm
weather icon
30° | 30°°C 0 mm 0% 7 mph 32 % 1017 mb 0 mm/h
Today 4:00 pm
weather icon
30° | 30°°C 0 mm 0% 9 mph 26 % 1015 mb 0 mm/h
Today 7:00 pm
weather icon
29° | 29°°C 0 mm 0% 9 mph 31 % 1014 mb 0 mm/h
Today 10:00 pm
weather icon
27° | 27°°C 0 mm 0% 2 mph 42 % 1014 mb 0 mm/h
Tomorrow 1:00 am
weather icon
24° | 24°°C 0 mm 0% 4 mph 56 % 1015 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,618.65
1.27%
Ethereum(ETH)
€2,138.27
3.19%
Tether(USDT)
€0.85
-0.01%
XRP(XRP)
€1.88
0.61%
Solana(SOL)
€129.93
1.86%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.143717
3.46%
Shiba Inu(SHIB)
€0.000010
1.75%
Pepe(PEPE)
€0.000009
6.23%
Scroll to Top