CVE-2024-5910: Expedition: Missing Authentication Leads to Admin Account Takeover (Severity: CRITICAL)
Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition.
Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.
Other sources
Palo Alto Networks Expedition contains a missing authentication vulnerability that allows an attacker with network access to takeover an Expedition admin account and potentially access configuration secrets, credentials, and other data.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Palo Alto Networks Expeditionto a version that resolves this vulnerability.Fixed in 1.2.92 - Compensating control
Restrict network access to Expedition to authorized users, hosts, or networks.
- Operational
Assume configuration secrets, credentials, and other data imported into Expedition are at risk; review and rotate any exposed credentials/secrets as appropriate.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5910?
CVE-2024-5910 is considered a critical vulnerability due to its potential to allow attackers to gain unauthorized access to an Expedition admin account.
How do I fix CVE-2024-5910?
To fix CVE-2024-5910, upgrade your Palo Alto Networks Expedition to version 1.2.92 or later.
What kind of attacks can CVE-2024-5910 enable?
CVE-2024-5910 can enable attackers with network access to take over the Expedition admin account, compromising the configuration management system.
What versions of Palo Alto Networks Expedition are affected by CVE-2024-5910?
CVE-2024-5910 affects all versions of Palo Alto Networks Expedition from 1.2.0 up to but not including 1.2.92.
Do I need to implement any additional security measures after updating for CVE-2024-5910?
It is recommended to review and enhance overall security practices in addition to updating to mitigate risks associated with CVE-2024-5910.