Critical Palo Alto Networks Expedition bug exploited (CVE-2024-5910)

Share:

A vulnerability (CVE-2024-5910) in Palo Alto Networks Expedition, a firewall configuration migration tool, is being exploited by attackers in the wild, the Cybersecurity and Infrastructure Security Agency (CISA) confirmed on Thursday.

About CVE-2024-5910

Unearthed and reported by Brian Hysell of Synopsys Cybersecurity Research Center (CyRC), CVE-2024-5910 stems from missing authentication for a critical function, which can lead to an Expedition admin account takeover for attackers with network access to the installation.

A security update fixing the vulnerability has been provided by Palo Alto Networks in July 2024. The company also advised those who couldn’t upgrade to make sure network access to their Expedition installation is restricted to authorized users, hosts, or networks.

The public disclosure of CVE-2024-5910 has spurred Horizon3.ai researchers to disclose (three months later) that the vulnerability could be exploited by sending a simple request to an exposed endpoint to reset the admin password:

CVE-2024-5910 exploited

Reseting the admin password (Source: Horizon3.ai)

They also decided to probe the tool for further weaknesses, and they found three:

  • CVE-2024-9464: An authenticated command injection
  • CVE-2024-9465: An unauthenticated SQL injection
  • CVE-2024-9466: Cleartext credentials in logs

Fixes for those vulnerabilities have been released in October 2024. But proof-of-concept exploit code for chaining the flaw with CVE-2024-9464 to achieve “unauthenticated” arbitrary command execution on vulnerable Expedition servers is publicly accessible.

What to do?

Whether CVE-2024-5910 is being exploited by itself or in conjunction with another vulnerability is unknown, because CISA didn’t share that information.

Palo Alto Networks has updated the advisory to say that they are “aware of reports from CISA that there is evidence of active exploitation for this CVE.”

If they haven’t already, users should upgrade their Expedition installation to a fixed version and make sure it is not exposed to the internet (as there is no reason for it).

Next, they should rotate all Expedition usernames, passwords, and API keys, as well as all firewall usernames, passwords, and API keys processed by Expedition.

Horizon3.ai’s Zach Hanley has previously explained how to check for indicators of compromise.

Zeljka Zorz

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
4:50 pm, Jun 29, 2025
weather icon 30°C
L: 28° | H: 31°
scattered clouds
Humidity: 44 %
Pressure: 1023 mb
Wind: 3 mph WSW
Wind Gust: 6 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 31%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:46 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
28° | 31°°C 0 mm 0% 8 mph 56 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
20° | 34°°C 0 mm 0% 7 mph 72 % 1022 mb 0 mm/h
Tue Jul 01 10:00 pm
weather icon
21° | 32°°C 0 mm 0% 14 mph 72 % 1017 mb 0 mm/h
Wed Jul 02 10:00 pm
weather icon
17° | 25°°C 1 mm 100% 9 mph 84 % 1019 mb 0 mm/h
Thu Jul 03 10:00 pm
weather icon
14° | 23°°C 0 mm 0% 8 mph 82 % 1025 mb 0 mm/h
Today 7:00 pm
weather icon
27° | 29°°C 0 mm 0% 2 mph 42 % 1022 mb 0 mm/h
Today 10:00 pm
weather icon
22° | 25°°C 0 mm 0% 8 mph 56 % 1022 mb 0 mm/h
Tomorrow 1:00 am
weather icon
21° | 21°°C 0 mm 0% 7 mph 70 % 1022 mb 0 mm/h
Tomorrow 4:00 am
weather icon
20° | 20°°C 0 mm 0% 3 mph 72 % 1021 mb 0 mm/h
Tomorrow 7:00 am
weather icon
21° | 21°°C 0 mm 0% 4 mph 65 % 1020 mb 0 mm/h
Tomorrow 10:00 am
weather icon
27° | 27°°C 0 mm 0% 5 mph 44 % 1019 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
33° | 33°°C 0 mm 0% 6 mph 30 % 1017 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
34° | 34°°C 0 mm 0% 7 mph 24 % 1015 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,078.20
0.56%
Ethereum(ETH)
€2,082.32
0.49%
Tether(USDT)
€0.85
0.00%
XRP(XRP)
€1.87
-0.59%
Solana(SOL)
€129.00
2.65%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.139651
0.86%
Shiba Inu(SHIB)
€0.000010
1.05%
Pepe(PEPE)
€0.000009
2.05%
Scroll to Top