Vulnerability record · CVE-2024-9463 · published 9 October 2024
CVE-2024-9463: Palo Alto Networks Expedition unauthenticated OS command injection
Paloaltonetworks · Expedition
Expedition contains an OS command injection flaw (CWE-78) that lets an unauthenticated attacker execute arbitrary OS commands as root. Because Expedition stores credentials and configuration for managed PAN-OS firewalls, compromise exposes sensitive firewall secrets. It is in CISA KEV with a very high EPSS score, so it is being actively targeted.
Description
An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:
Automated analysis
critical priorityUnauthenticated remote root command execution with KEV listing and near-maximum EPSS makes this an urgent, actively exploited risk.
What it is
Expedition contains an OS command injection flaw (CWE-78) that lets an unauthenticated attacker execute arbitrary OS commands as root. Because Expedition stores credentials and configuration for managed PAN-OS firewalls, compromise exposes sensitive firewall secrets. It is in CISA KEV with a very high EPSS score, so it is being actively targeted.
Impact
An attacker gains root-level command execution on the Expedition server and can read usernames, cleartext passwords, device configurations and PAN-OS firewall API keys. Those secrets can be used to pivot into managed firewalls.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS 4.0 vector (AV:N/PR:N/UI:N). Any network-exposed Expedition instance is directly at risk.
Exploitation
Listed in CISA KEV (added 2024-11-14) and EPSS 30-day probability is 0.985 (99.9th percentile), indicating observed exploitation and high likelihood of continued attacks. No ransomware campaign use is documented in the record.
What to do
- Apply the vendor fix per Palo Alto Networks advisory PAN-SA-2024-0010; patch or upgrade Expedition immediately.
- If no fix is available, follow CISA guidance and discontinue use of Expedition until it can be remediated.
- Restrict network access to Expedition management interfaces to trusted hosts only; never expose it to the internet.
- Rotate all credentials, PAN-OS device API keys and configurations that were stored or processed by the affected Expedition instance.
- Monitor vendor advisory for updated mitigations and re-check exposure after patching.
Detection
- Hunt for unexpected child processes spawned by Expedition web/application processes, especially shells (sh, bash) or command interpreters.
- Review Expedition server logs and web access logs for anomalous requests or command-like parameters preceding process creation.
- Alert on outbound connections from the Expedition host to unknown destinations, which may indicate exfiltration of credentials or configs.
- Audit for access to stored credential/config files on the Expedition host and correlate with process execution events.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-9463 to the Known Exploited Vulnerabilities catalog on 14 November 2024 as "Palo Alto Networks Expedition OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 5 December 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://security.paloaltonetworks.com/PAN-SA-2024-0010 | MitigationVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-9463 | US Government Resource |
Track CVE-2024-9463 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-9463), CISA KEV, FIRST EPSS (scores of 2026-09-21). This page is refreshed as NVD updates the record.