Vulnerability record · CVE-2024-9465 · published 9 October 2024
CVE-2024-9465: Palo Alto Networks Expedition unauthenticated SQL injection
Paloaltonetworks · Expedition
Expedition contains a SQL injection flaw reachable without authentication. It lets an attacker read the Expedition database, exposing password hashes, usernames, device configurations and device API keys, and also create and read arbitrary files on the system. Because the data exposed feeds downstream firewall management, the exposure extends beyond the Expedition host itself.
Description
An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:
Automated analysis
critical priorityUnauthenticated network-reachable SQL injection with high confidentiality impact, KEV listing, and near-maximum EPSS.
What it is
Expedition contains a SQL injection flaw reachable without authentication. It lets an attacker read the Expedition database, exposing password hashes, usernames, device configurations and device API keys, and also create and read arbitrary files on the system. Because the data exposed feeds downstream firewall management, the exposure extends beyond the Expedition host itself.
Impact
An attacker gains read access to sensitive Expedition data including credential hashes and device API keys, plus the ability to create and read arbitrary files on the Expedition system. That data can be used to pivot into managed firewall infrastructure.
Attack surface
Reachable over the network with no authentication and no user interaction, per the CVSS 4.0 vector (AV:N/PR:N/UI:N). The description does not specify the exact endpoint or parameter, so the precise injection point is not stated in this record.
Exploitation
Listed in CISA KEV with a due date of 2024-12-05, and EPSS is 0.99626 (99.9th percentile), indicating active exploitation and very high likelihood. A public exploit write-up is referenced by Horizon3.
What to do
- Apply the vendor fix per Palo Alto Networks advisory PAN-SA-2024-0010; if no fix is available for your version, discontinue use of Expedition as CISA directs.
- Restrict network access to Expedition to trusted management hosts only; it should not be internet-facing.
- Rotate credentials and device API keys that were stored in or processed by Expedition, and review device configurations for tampering.
- Monitor and audit files created on the Expedition host for signs of arbitrary file writes.
- If Expedition is not actively needed, decommission it rather than leaving it exposed.
Detection
- Review Expedition and web server logs for anomalous SQL syntax or injection patterns in request parameters.
- Alert on unexpected file creation or modification on the Expedition host, especially outside normal application paths.
- Monitor for outbound connections from Expedition to unfamiliar hosts that could indicate data exfiltration.
- Hunt for use of credentials or API keys originating from Expedition against managed firewall devices.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-9465 to the Known Exploited Vulnerabilities catalog on 14 November 2024 as "Palo Alto Networks Expedition SQL Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 5 December 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://security.paloaltonetworks.com/PAN-SA-2024-0010 | MitigationVendor Advisory |
| https://www.horizon3.ai/attack-research/palo-alto-expedition-from-n-day-to-full-compromise/ | Exploit |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-9465 | US Government Resource |
Track CVE-2024-9465 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-9465), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.