Record summary

CVE-2024-9463 has a selected CVSS score of 9.9 (critical); EIP currently links 1 repository PoC and 1 Nuclei template. CISA lists CVE-2024-9463 in KEV.

Description

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Nov 14, 2024 · CISA
VulnCheck KEV
Listed · Oct 15, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationActive
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 20, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CISA, CVE List1.2.0 to < 1.2.96affected

Proofs of concept

1

Repository PoCs

GitHubmomo1239/CVE-2024-9463-Proof-of-ConceptRepository PoCby momo1239Stars: 1Not analyzed2 files

3.3 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALPaloAlto Networks Expedition - Remote Code ExecutionCVSS 9.9

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

Impact

Successful exploitation could result in unauthorized access and control of the affected device.

Remediation

Apply the necessary security patches provided by Palo Alto Networks to mitigate the CVE-2024-9463 vulnerability.

WeaknessesCWE-78
Authorsprincechaddha
Template tagscvecve2024palo-altorcekevvkevvuln
CVSS vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/S
Shodan: http.favicon.hash:1499876150

Source: ProjectDiscovery

References

3