CVE-2024-9465: Palo Alto Networks Expedition SQL Injection Vulnerability
An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.
Other sources
Palo Alto Networks Expedition contains a SQL injection vulnerability that allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Palo Alto Networks Expeditionto a version that resolves this vulnerability.Fixed in 1.2.96 - Compensating control
Discontinue use of the product if mitigations are unavailable.
- Operational
Rotate all Expedition usernames, passwords, and API keys after upgrading to Expedition 1.2.96 (or later).
- Operational
Rotate all firewall usernames, passwords, and API keys processed by Expedition after updating.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9465?
CVE-2024-9465 is classified as a high-severity SQL injection vulnerability.
How do I fix CVE-2024-9465?
To fix CVE-2024-9465, upgrade Palo Alto Networks Expedition to version 1.2.96 or later.
What types of data are at risk due to CVE-2024-9465?
CVE-2024-9465 exposes sensitive data including password hashes, usernames, and device API keys.
Who is affected by CVE-2024-9465?
CVE-2024-9465 affects all versions of Palo Alto Networks Expedition from 1.2.0 up to 1.2.96.
Can an attacker exploit CVE-2024-9465 remotely?
Yes, CVE-2024-9465 can be exploited by unauthenticated attackers remotely.