Critical Palo Alto Networks Expedition bug exploited (CVE-2024-5910)

Teilen:

A vulnerability (CVE-2024-5910) in Palo Alto Networks Expedition, a firewall configuration migration tool, is being exploited by attackers in the wild, the Cybersecurity and Infrastructure Security Agency (CISA) confirmed on Thursday.

About CVE-2024-5910

Unearthed and reported by Brian Hysell of Synopsys Cybersecurity Research Center (CyRC), CVE-2024-5910 stems from missing authentication for a critical function, which can lead to an Expedition admin account takeover for attackers with network access to the installation.

A security update fixing the vulnerability has been provided by Palo Alto Networks in July 2024. The company also advised those who couldn’t upgrade to make sure network access to their Expedition installation is restricted to authorized users, hosts, or networks.

The public disclosure of CVE-2024-5910 has spurred Horizon3.ai researchers to disclose (three months later) that the vulnerability could be exploited by sending a simple request to an exposed endpoint to reset the admin password:

CVE-2024-5910 exploited

Reseting the admin password (Source: Horizon3.ai)

They also decided to probe the tool for further weaknesses, and they found three:

  • CVE-2024-9464: An authenticated command injection
  • CVE-2024-9465: An unauthenticated SQL injection
  • CVE-2024-9466: Cleartext credentials in logs

Fixes for those vulnerabilities have been released in October 2024. But proof-of-concept exploit code for chaining the flaw with CVE-2024-9464 to achieve “unauthenticated” arbitrary command execution on vulnerable Expedition servers is publicly accessible.

What to do?

Whether CVE-2024-5910 is being exploited by itself or in conjunction with another vulnerability is unknown, because CISA didn’t share that information.

Palo Alto Networks has updated the advisory to say that they are “aware of reports from CISA that there is evidence of active exploitation for this CVE.”

If they haven’t already, users should upgrade their Expedition installation to a fixed version and make sure it is not exposed to the internet (as there is no reason for it).

Next, they should rotate all Expedition usernames, passwords, and API keys, as well as all firewall usernames, passwords, and API keys processed by Expedition.

Horizon3.ai’s Zach Hanley has previously explained how to check for indicators of compromise.

Zeljka Zorz

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
11:09 am, Juli 13, 2025
Wetter-Symbol 23°C
L: 21° | H: 24°
klarer Himmel
Luftfeuchtigkeit: 69 %
Druck: 1013 mb
Wind: 4 mph NE
Windböe: 4 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 3%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:58 am
Sonnenuntergang: 9:13 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
21° | 24°°C 0 mm 0% 6 mph 62 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
19° | 27°°C 0 mm 0% 15 mph 71 % 1015 mb 0 mm/h
Di. Juli 15 10:00 pm
Wetter-Symbol
15° | 22°°C 1 mm 100% 17 mph 85 % 1016 mb 0 mm/h
Mi. Juli 16 10:00 pm
Wetter-Symbol
14° | 27°°C 0.11 mm 11% 11 mph 85 % 1017 mb 0 mm/h
Do. Juli 17 10:00 pm
Wetter-Symbol
18° | 27°°C 1 mm 100% 13 mph 95 % 1015 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
24° | 26°°C 0 mm 0% 3 mph 62 % 1013 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
27° | 29°°C 0 mm 0% 0 mph 47 % 1011 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 6 mph 31 % 1008 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 6 mph 40 % 1010 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 5 mph 40 % 1011 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 5 mph 52 % 1010 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 9 mph 71 % 1011 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
23° | 23°°C 0 mm 0% 12 mph 54 % 1012 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€100,792.44
-0.22%
Ethereum(ETH)
€2,525.09
-0.71%
XRP(XRP)
€2.38
-1.26%
Fesseln(USDT)
€0.86
0.00%
Solana(SOL)
€138.56
-0.40%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.168584
-2.60%
Shiba Inu(SHIB)
€0.000011
-2.40%
Pepe(PEPE)
€0.000010
-2.76%
Peanut das Eichhörnchen(PNUT)
€0.246209
7.19%
Nach oben scrollen