← Vulnerability feed

Vulnerability record · CVE-2024-5910 · published 10 July 2024

CVE-2024-5910: Palo Alto Networks Expedition missing authentication allows admin takeover

Paloaltonetworks · Expedition

Expedition, Palo Alto Networks' configuration migration and tuning tool, exposes a critical function without requiring authentication. An attacker with network access can take over an Expedition admin account, and because imported configuration secrets and credentials live in the tool, those are also at risk.

9.3 CVSS 4.0 Critical CISA KEV since 7 Nov 2024 EPSS 92% · top 0.2% CWE-306 · Missing authentication for critical function
9.3CVSS 4.0 base score
92%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
4References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable admin takeover with CVSS 9.3, KEV listing and very high EPSS, and it exposes imported credentials.

What it is

Expedition, Palo Alto Networks' configuration migration and tuning tool, exposes a critical function without requiring authentication. An attacker with network access can take over an Expedition admin account, and because imported configuration secrets and credentials live in the tool, those are also at risk.

Impact

An attacker gains full administrative control of Expedition and access to the credentials and configuration secrets imported into it, which can extend compromise to managed firewalls and other infrastructure.

Attack surface

Reachable over the network with no authentication and no user interaction, per the CVSS 4.0 vector (AV:N/PR:N/UI:N). Any host that can reach the Expedition interface can attempt it.

Exploitation

Listed in CISA KEV since 2024-11-07 with a required action deadline of 2024-11-28, and EPSS 30-day probability is about 0.918 (99.8th percentile). A public third-party advisory is tagged as an exploit reference, indicating known exploitation activity.

What to do

  • Apply the vendor fix from the Palo Alto Networks advisory for CVE-2024-5910; if no fix is available for your deployment, discontinue use of Expedition as CISA directs.
  • Restrict network access to the Expedition interface to trusted management hosts only; do not expose it to untrusted networks or the internet.
  • Rotate all credentials, secrets and configuration data imported into Expedition, and any device credentials those imports contain, assuming exposure.
  • Monitor and audit Expedition admin accounts for unauthorized creation or changes, and review logs for unexpected administrative activity.
  • If Expedition is no longer needed, decommission it and remove its stored configuration data.

Detection

  • Hunt for unexpected or newly created Expedition admin accounts and authentication events from unfamiliar source IPs.
  • Review network logs for connections to the Expedition management interface from outside approved management ranges.
  • Search for signs of credential use from Expedition-imported secrets against managed Palo Alto Networks devices.
  • Correlate host and network telemetry around Expedition for post-exploitation activity following unauthenticated access.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-5910 to the Known Exploited Vulnerabilities catalog on 7 November 2024 as "Palo Alto Networks Expedition Missing Authentication Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 28 November 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-5910 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2024-9463Palo Alto Networks Expedition unauthenticated OS command injectionExpedition contains an OS command injection flaw (CWE-78) that lets an unauthenticated attacker execute arbitrary OS commands as root. Because Expedi…KEVEPSS 99%analysed9.2CVE-2024-9465Palo Alto Networks Expedition unauthenticated SQL injectionExpedition contains a SQL injection flaw reachable without authentication. It lets an attacker read the Expedition database, exposing password hashes…KEVEPSS 100%analysed9.8CVE-2018-10143Paloaltonetworks expedition improper privilege management vulnerabilityThe Palo Alto Networks Expedition Migration tool 1.0.107 and earlier may allow an unauthenticated attacker with remote access to run system level com…EPSS 25%9.3CVE-2024-9464Palo Alto Networks Expedition OS command injection as rootExpedition contains an OS command injection flaw (CWE-78) that lets an authenticated attacker execute arbitrary operating system commands with root p…EPSS 83%analysed9.2CVE-2025-0103Paloaltonetworks expedition sql injection vulnerabilityAn SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as pas…EPSS 0.62%8.2CVE-2024-9466Paloaltonetworks expedition sensitive information in log file vulnerabilityA cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usern…EPSS 14%7.7CVE-2025-0107Palo Alto Networks Expedition unauthenticated OS command injectionExpedition contains an OS command injection flaw (CWE-78) that lets an unauthenticated remote attacker execute arbitrary OS commands as the www-data …EPSS 79%analysed7.5CVE-2018-10142Paloaltonetworks expedition information exposure vulnerabilityThe Expedition Migration tool 1.0.106 and earlier may allow an unauthenticated attacker to enumerate files on the operating system.EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2024-5910), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.