← Vulnerability feed

Vulnerability record · CVE-2024-9463 · published 9 October 2024

CVE-2024-9463: Palo Alto Networks Expedition unauthenticated OS command injection

Paloaltonetworks · Expedition

Expedition contains an OS command injection flaw (CWE-78) that lets an unauthenticated attacker execute arbitrary OS commands as root. Because Expedition stores credentials and configuration for managed PAN-OS firewalls, compromise exposes sensitive firewall secrets. It is in CISA KEV with a very high EPSS score, so it is being actively targeted.

9.9 CVSS 4.0 Critical CISA KEV since 14 Nov 2024 EPSS 99% · top 0.1% CWE-78 · OS command injection
9.9CVSS 4.0 base score
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated remote root command execution with KEV listing and near-maximum EPSS makes this an urgent, actively exploited risk.

What it is

Expedition contains an OS command injection flaw (CWE-78) that lets an unauthenticated attacker execute arbitrary OS commands as root. Because Expedition stores credentials and configuration for managed PAN-OS firewalls, compromise exposes sensitive firewall secrets. It is in CISA KEV with a very high EPSS score, so it is being actively targeted.

Impact

An attacker gains root-level command execution on the Expedition server and can read usernames, cleartext passwords, device configurations and PAN-OS firewall API keys. Those secrets can be used to pivot into managed firewalls.

Attack surface

Reachable over the network with no authentication and no user interaction required, per the CVSS 4.0 vector (AV:N/PR:N/UI:N). Any network-exposed Expedition instance is directly at risk.

Exploitation

Listed in CISA KEV (added 2024-11-14) and EPSS 30-day probability is 0.985 (99.9th percentile), indicating observed exploitation and high likelihood of continued attacks. No ransomware campaign use is documented in the record.

What to do

  • Apply the vendor fix per Palo Alto Networks advisory PAN-SA-2024-0010; patch or upgrade Expedition immediately.
  • If no fix is available, follow CISA guidance and discontinue use of Expedition until it can be remediated.
  • Restrict network access to Expedition management interfaces to trusted hosts only; never expose it to the internet.
  • Rotate all credentials, PAN-OS device API keys and configurations that were stored or processed by the affected Expedition instance.
  • Monitor vendor advisory for updated mitigations and re-check exposure after patching.

Detection

  • Hunt for unexpected child processes spawned by Expedition web/application processes, especially shells (sh, bash) or command interpreters.
  • Review Expedition server logs and web access logs for anomalous requests or command-like parameters preceding process creation.
  • Alert on outbound connections from the Expedition host to unknown destinations, which may indicate exfiltration of credentials or configs.
  • Audit for access to stored credential/config files on the Expedition host and correlate with process execution events.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-9463 to the Known Exploited Vulnerabilities catalog on 14 November 2024 as "Palo Alto Networks Expedition OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 5 December 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-9463 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2024-5910Palo Alto Networks Expedition missing authentication allows admin takeoverExpedition, Palo Alto Networks' configuration migration and tuning tool, exposes a critical function without requiring authentication. An attacker wi…KEVEPSS 92%analysed9.2CVE-2024-9465Palo Alto Networks Expedition unauthenticated SQL injectionExpedition contains a SQL injection flaw reachable without authentication. It lets an attacker read the Expedition database, exposing password hashes…KEVEPSS 100%analysed9.8CVE-2018-10143Paloaltonetworks expedition improper privilege management vulnerabilityThe Palo Alto Networks Expedition Migration tool 1.0.107 and earlier may allow an unauthenticated attacker with remote access to run system level com…EPSS 25%9.3CVE-2024-9464Palo Alto Networks Expedition OS command injection as rootExpedition contains an OS command injection flaw (CWE-78) that lets an authenticated attacker execute arbitrary operating system commands with root p…EPSS 83%analysed9.2CVE-2025-0103Paloaltonetworks expedition sql injection vulnerabilityAn SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as pas…EPSS 0.62%8.2CVE-2024-9466Paloaltonetworks expedition sensitive information in log file vulnerabilityA cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usern…EPSS 14%7.7CVE-2025-0107Palo Alto Networks Expedition unauthenticated OS command injectionExpedition contains an OS command injection flaw (CWE-78) that lets an unauthenticated remote attacker execute arbitrary OS commands as the www-data …EPSS 79%analysed7.5CVE-2018-10142Paloaltonetworks expedition information exposure vulnerabilityThe Expedition Migration tool 1.0.106 and earlier may allow an unauthenticated attacker to enumerate files on the operating system.EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2024-9463), CISA KEV, FIRST EPSS (scores of 2026-09-21). This page is refreshed as NVD updates the record.