Palo Alto Networks disclosed multiple vulnerabilities in its Expedition migration tool that can expose sensitive firewall data and enable further compromise of managed environments. The issues affect Expedition versions earlier than 1.2.101, with the most severe flaw tracked as CVE-2025-0103. Reported impacts include unauthorized access to sensitive information, file creation and deletion, file enumeration, session theft, and command injection.
The risk is heightened because Expedition databases and files can store PAN-OS firewall credentials, configuration data, and API keys, creating a path for follow-on attacks against production firewalls. Palo Alto said Expedition support ended on December 31, 2024, and urged organizations to upgrade immediately to version 1.2.101 and move to supported alternative products to reduce exposure.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks released security updates for five vulnerabilities affecting Expedition versions earlier than 1.2.101, including CVE-2025-0103. The flaws could allow unauthorized access to sensitive data, file operations, session theft, and command injection, with risk heightened by stored firewall credentials and API keys.
Palo Alto Networks stated that support for the Expedition migration tool ended on December 31, 2024, and advised customers to migrate to supported alternatives.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcesecurity.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.