← Back to browse · API

CVE-2024-9463

Severity
CRITICAL
CVSS
9.9
EPSS
0.98494
Risk score
59.47
CISA KEV
Yes
PoC
No
Published
2024-10-09
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2024-49955, GHSA-R2FH-MJ7F-V33R
Products
Palo Alto Networks:Expedition, Palo Alto Networks:Expedition 1.2.0 <1.2.96
Sources
cisa.gov CVE-2024-9463
euvd EUVD-2024-49955

Description

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

References