Palo Alto Networks disclosed multiple critical vulnerabilities in its Expedition migration tool that can expose sensitive data and let attackers compromise firewall administration. The flaws affect Expedition versions earlier than 1.2.96 and include root command execution, unauthenticated root command execution, SQL database data extraction, authenticated access to confidential information, and an XSS issue that can enable browser session hijacking. Palo Alto said the bugs do not directly affect its firewalls, Panorama, Prisma Access, or Cloud NGFW products.
The company released Expedition version 1.2.96 to fix the issues and urged customers to rotate all usernames, passwords, and PAN-OS firewall API keys processed by Expedition after upgrading. Palo Alto also advised restricting network access to Expedition to authorized users only and reviewing systems for signs of compromise, including suspicious activity and indicators tied to CVE-2024-9465, such as entries in the cronjobs table.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks released Expedition version 1.2.96 to remediate the disclosed vulnerabilities. The company advised customers to rotate usernames, passwords, and API keys handled by Expedition after upgrading, restrict network access to authorized users, and review systems for signs of compromise such as suspicious cronjob entries related to CVE-2024-9465.
Palo Alto Networks published advisory PAN-SA-2024-0010 disclosing multiple critical vulnerabilities in its Expedition migration tool affecting versions earlier than 1.2.96. The flaws could enable root command execution, database data extraction, access to confidential information, XSS-based session hijacking, and takeover of firewall administrator accounts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
kyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.