PAN-SA-2025-0001: Expedition: Multiple Vulnerabilities in Expedition Migration Tool Lead to Exposure of Firewall Credentials
Multiple vulnerabilities in the Palo Alto Networks Expedition migration tool enable an attacker to read Expedition database contents and arbitrary files, as well as create and delete arbitrary files on the Expedition system. These files include information such as usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.
Expedition, previously known as the Migration Tool, is a free tool that facilitates migration to the Palo Alto Networks NGFW platform from other firewall vendors and provides a temporary workspace for optimizing Palo Alto Networks security policies. Expedition is designed to only be used temporarily for migration purposes, not to be run in production. You do not need it to operate any Palo Alto Networks products or services. Expedition reached its End of Life (EoL) date on December 31, 2024. Please use the suggested alternatives listed in the Expedition End of Life Announcement (https://live.paloaltonetworks.com/t5/expedition-articles/important-update-end-of-life-announcement-for-palo-alto-networks/ta-p/589642).
These issues do not otherwise impact firewalls, Panorama appliances, Prisma Access deployments, or Cloud NGFWs.
Affected Software
Remediation
Mitigation
Information
Event History
Frequently Asked Questions
What is the severity of PAN-SA-2025-0001?
The severity of PAN-SA-2025-0001 is considered high due to the potential for unauthorized file access and manipulation.
How do I fix PAN-SA-2025-0001?
To fix PAN-SA-2025-0001, upgrade the Palo Alto Networks Expedition to version 1.2.101 or later immediately.
What vulnerabilities are associated with PAN-SA-2025-0001?
PAN-SA-2025-0001 includes multiple vulnerabilities that allow attackers to read Expedition database contents, read arbitrary files, and create or delete files.
Which products are affected by PAN-SA-2025-0001?
The products affected by PAN-SA-2025-0001 include Palo Alto Networks Expedition versions up to 1.2.101, Cloud NGFW, Panorama, PAN-OS, and Prisma Access.
How can an attacker exploit PAN-SA-2025-0001?
An attacker can exploit PAN-SA-2025-0001 to gain unauthorized access to sensitive information and manipulate files on the Expedition system.