Back

CRITICAL KEV

Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure

Published Oct 9, 2024 ·Due Dec 5, 2024

Description

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

Affected products

Remediation

Vendor solution

The fixes for all listed issues are available in Expedition 1.2.96, and all later Expedition versions.

All Expedition usernames, passwords, and API keys should be rotated after upgrading to the fixed version of Expedition.

All firewall usernames, passwords, and API keys processed by Expedition should be rotated after updating.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner palo_alto
Published Oct 9, 2024
Updated Oct 21, 2025
Reserved Oct 3, 2024
CISA Vulnrichment
Updated Aug 20, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a