← Back to browse · API

CVE-2024-9464

Severity
CRITICAL
CVSS
9.3
EPSS
0.81845
Risk score
65.85
CISA KEV
No
PoC
No
Published
2024-10-09
Modified
2024-10-18
First seen
2026-08-07
Aliases
EUVD-2024-49956, GHSA-R7WF-FPFF-W68Q
Products
Palo Alto Networks:Expedition 1.2.0 <1.2.96
Sources
euvd EUVD-2024-49956

Description

An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

References