CVE-2024-9463
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
Record summary
CVE-2024-9463 has a selected CVSS score of 9.9 (critical); EIP currently links 1 repository PoC and 1 Nuclei template. CISA lists CVE-2024-9463 in KEV.
Description
An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.
Exploitation context
Known exploitation
- CISA KEV
- Listed · Nov 14, 2024 · CISA
- VulnCheck KEV
- Listed · Oct 15, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 20, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ExpeditionBrowse Palo Alto Networks / ExpeditionDefault status: unaffected | CISA, CVE List | 1.2.0 to < 1.2.96 | affected |
Proofs of concept
1Repository PoCs
GitHubmomo1239/CVE-2024-9463-Proof-of-ConceptRepository PoCby momo1239Stars: 1Not analyzed2 files
Nuclei templates
1ProjectDiscoveryCRITICALPaloAlto Networks Expedition - Remote Code ExecutionCVSS 9.9
An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.
Impact
Successful exploitation could result in unauthorized access and control of the affected device.
Remediation
Apply the necessary security patches provided by Palo Alto Networks to mitigate the CVE-2024-9463 vulnerability.
Source: ProjectDiscovery