SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-5910

Palo Alto Networks Expedition Missing Authentication Vulnerability

KEVCRITICAL 9.3EPSS 91.8%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 28 November 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.

CVSS 4.0
9.3 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
91.78% probability · 100th percentile
CISA KEV
Listed 7 November 2024 · due 28 November 2024
Weakness
CWE-306
Affected
paloaltonetworks/expedition
Source
psirt@paloaltonetworks.com

CISA notes

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://security.paloaltonetworks.com/CVE-2024-5910 ; https://nvd.nist.gov/vuln/detail/CVE-2024-5910

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.