Vulnerability record · CVE-2024-5910 · published 10 July 2024
CVE-2024-5910: Palo Alto Networks Expedition missing authentication allows admin takeover
Paloaltonetworks · Expedition
Expedition, Palo Alto Networks' configuration migration and tuning tool, exposes a critical function without requiring authentication. An attacker with network access can take over an Expedition admin account, and because imported configuration secrets and credentials live in the tool, those are also at risk.
Description
Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:
Automated analysis
critical priorityUnauthenticated network-reachable admin takeover with CVSS 9.3, KEV listing and very high EPSS, and it exposes imported credentials.
What it is
Expedition, Palo Alto Networks' configuration migration and tuning tool, exposes a critical function without requiring authentication. An attacker with network access can take over an Expedition admin account, and because imported configuration secrets and credentials live in the tool, those are also at risk.
Impact
An attacker gains full administrative control of Expedition and access to the credentials and configuration secrets imported into it, which can extend compromise to managed firewalls and other infrastructure.
Attack surface
Reachable over the network with no authentication and no user interaction, per the CVSS 4.0 vector (AV:N/PR:N/UI:N). Any host that can reach the Expedition interface can attempt it.
Exploitation
Listed in CISA KEV since 2024-11-07 with a required action deadline of 2024-11-28, and EPSS 30-day probability is about 0.918 (99.8th percentile). A public third-party advisory is tagged as an exploit reference, indicating known exploitation activity.
What to do
- Apply the vendor fix from the Palo Alto Networks advisory for CVE-2024-5910; if no fix is available for your deployment, discontinue use of Expedition as CISA directs.
- Restrict network access to the Expedition interface to trusted management hosts only; do not expose it to untrusted networks or the internet.
- Rotate all credentials, secrets and configuration data imported into Expedition, and any device credentials those imports contain, assuming exposure.
- Monitor and audit Expedition admin accounts for unauthorized creation or changes, and review logs for unexpected administrative activity.
- If Expedition is no longer needed, decommission it and remove its stored configuration data.
Detection
- Hunt for unexpected or newly created Expedition admin accounts and authentication events from unfamiliar source IPs.
- Review network logs for connections to the Expedition management interface from outside approved management ranges.
- Search for signs of credential use from Expedition-imported secrets against managed Palo Alto Networks devices.
- Correlate host and network telemetry around Expedition for post-exploitation activity following unauthenticated access.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-5910 to the Known Exploited Vulnerabilities catalog on 7 November 2024 as "Palo Alto Networks Expedition Missing Authentication Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 28 November 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://security.paloaltonetworks.com/CVE-2024-5910 | Vendor Advisory |
| https://security.paloaltonetworks.com/CVE-2024-5910 | Vendor Advisory |
| https://www.horizon3.ai/attack-research/palo-alto-expedition-from-n-day-to-full-compromise | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-5910 | US Government Resource |
Track CVE-2024-5910 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-5910), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.