← Vulnerability feed

Vulnerability record · CVE-2024-9465 · published 9 October 2024

CVE-2024-9465: Palo Alto Networks Expedition unauthenticated SQL injection

Paloaltonetworks · Expedition

Expedition contains a SQL injection flaw reachable without authentication. It lets an attacker read the Expedition database, exposing password hashes, usernames, device configurations and device API keys, and also create and read arbitrary files on the system. Because the data exposed feeds downstream firewall management, the exposure extends beyond the Expedition host itself.

9.2 CVSS 4.0 Critical CISA KEV since 14 Nov 2024 EPSS 100% · top 0.1% CWE-89 · SQL injection
9.2CVSS 4.0 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable SQL injection with high confidentiality impact, KEV listing, and near-maximum EPSS.

What it is

Expedition contains a SQL injection flaw reachable without authentication. It lets an attacker read the Expedition database, exposing password hashes, usernames, device configurations and device API keys, and also create and read arbitrary files on the system. Because the data exposed feeds downstream firewall management, the exposure extends beyond the Expedition host itself.

Impact

An attacker gains read access to sensitive Expedition data including credential hashes and device API keys, plus the ability to create and read arbitrary files on the Expedition system. That data can be used to pivot into managed firewall infrastructure.

Attack surface

Reachable over the network with no authentication and no user interaction, per the CVSS 4.0 vector (AV:N/PR:N/UI:N). The description does not specify the exact endpoint or parameter, so the precise injection point is not stated in this record.

Exploitation

Listed in CISA KEV with a due date of 2024-12-05, and EPSS is 0.99626 (99.9th percentile), indicating active exploitation and very high likelihood. A public exploit write-up is referenced by Horizon3.

What to do

  • Apply the vendor fix per Palo Alto Networks advisory PAN-SA-2024-0010; if no fix is available for your version, discontinue use of Expedition as CISA directs.
  • Restrict network access to Expedition to trusted management hosts only; it should not be internet-facing.
  • Rotate credentials and device API keys that were stored in or processed by Expedition, and review device configurations for tampering.
  • Monitor and audit files created on the Expedition host for signs of arbitrary file writes.
  • If Expedition is not actively needed, decommission it rather than leaving it exposed.

Detection

  • Review Expedition and web server logs for anomalous SQL syntax or injection patterns in request parameters.
  • Alert on unexpected file creation or modification on the Expedition host, especially outside normal application paths.
  • Monitor for outbound connections from Expedition to unfamiliar hosts that could indicate data exfiltration.
  • Hunt for use of credentials or API keys originating from Expedition against managed firewall devices.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-9465 to the Known Exploited Vulnerabilities catalog on 14 November 2024 as "Palo Alto Networks Expedition SQL Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 5 December 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-9465 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2024-9463Palo Alto Networks Expedition unauthenticated OS command injectionExpedition contains an OS command injection flaw (CWE-78) that lets an unauthenticated attacker execute arbitrary OS commands as root. Because Expedi…KEVEPSS 99%analysed9.3CVE-2024-5910Palo Alto Networks Expedition missing authentication allows admin takeoverExpedition, Palo Alto Networks' configuration migration and tuning tool, exposes a critical function without requiring authentication. An attacker wi…KEVEPSS 92%analysed9.8CVE-2018-10143Paloaltonetworks expedition improper privilege management vulnerabilityThe Palo Alto Networks Expedition Migration tool 1.0.107 and earlier may allow an unauthenticated attacker with remote access to run system level com…EPSS 25%9.3CVE-2024-9464Palo Alto Networks Expedition OS command injection as rootExpedition contains an OS command injection flaw (CWE-78) that lets an authenticated attacker execute arbitrary operating system commands with root p…EPSS 83%analysed9.2CVE-2025-0103Paloaltonetworks expedition sql injection vulnerabilityAn SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as pas…EPSS 0.62%8.2CVE-2024-9466Paloaltonetworks expedition sensitive information in log file vulnerabilityA cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usern…EPSS 14%7.7CVE-2025-0107Palo Alto Networks Expedition unauthenticated OS command injectionExpedition contains an OS command injection flaw (CWE-78) that lets an unauthenticated remote attacker execute arbitrary OS commands as the www-data …EPSS 79%analysed7.5CVE-2018-10142Paloaltonetworks expedition information exposure vulnerabilityThe Expedition Migration tool 1.0.106 and earlier may allow an unauthenticated attacker to enumerate files on the operating system.EPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2024-9465), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.