PAN-SA-2024-0010: Expedition: Multiple Vulnerabilities in Expedition Lead to Exposure of Firewall Credentials (Severity: CRITICAL)
Multiple vulnerabilities in Palo Alto Networks Expedition allow an attacker to read Expedition database contents and arbitrary files, as well as write arbitrary files to temporary storage locations on the Expedition system. Combined, these include information such as usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.
These issues do not affect the firewalls, Panorama, Prisma Access, or Cloud NGFW.
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of PAN-SA-2024-0010?
The severity of PAN-SA-2024-0010 is considered critical due to the potential for unauthorized access to sensitive data.
How do I fix PAN-SA-2024-0010?
To fix PAN-SA-2024-0010, upgrade your Palo Alto Networks Expedition software to the latest version that is not vulnerable.
What products are affected by PAN-SA-2024-0010?
The affected products include Palo Alto Networks Expedition version 1.2.96 and earlier, as well as Cloud NGFW, Panorama, PAN-OS, and Prisma Access.
What types of information could be compromised due to PAN-SA-2024-0010?
Due to PAN-SA-2024-0010, attackers could potentially access usernames and other sensitive database contents.
Can PAN-SA-2024-0010 lead to file manipulation?
Yes, PAN-SA-2024-0010 allows attackers to write arbitrary files to temporary storage locations on the Expedition system.