CVE-2024-5910

Expedition: Missing Authentication Leads to Admin Account Takeover

Severity
Critical 9.3
CVSS 4.0
Exploited
Yes — in CISA KEV
Added Nov 7, 2024
EPSS
0.918
99.8th percentile
Discovered by
Third party
Published by the vendor
Published
Jul 10, 2024
Assigned by palo_alto

Description

Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.

Weakness: CWE-306

Affected products

Vendor Product Category Matched by
Palo Alto Networks Expedition Network & Security Management cna-assigner
Vendor-reported affected versions (2)
  • Palo Alto Networks · Expedition
  • paloaltonetworks · expedition

Credit

Brian Hysell (Synopsys CyRC)

Vendor remediation

This issue is fixed in Expedition 1.2.92 and all later versions.