CVE-2018-10143

CRITICAL

Palo Alto Networks Expedition <= 1.0.107 - Unauthenticated Remote Code Execution

Title source: llm
STIX 2.1

Description

The Palo Alto Networks Expedition Migration tool 1.0.107 and earlier may allow an unauthenticated attacker with remote access to run system level commands on the device hosting this service/application.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106174
Various Sources x_refsource_confirm
https://security.paloaltonetworks.com/CVE-2018-10143

Scores

CVSS v3 9.8
EPSS 0.2813
EPSS Percentile 96.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-269
Status published
Products (1)
paloaltonetworks/expedition 1.0.107
Published Dec 12, 2018
Tracked Since Feb 18, 2026