Security
Loading…

CVE-2024-9465

UNKNOWNKnown Exploited
Description

Palo Alto Networks Expedition contains a SQL injection vulnerability that allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.

Timeline
Published:November 14th, 2024 12:00 AM
Last modified:November 14th, 2024 12:00 AM
Added to KEV:November 14th, 2024
CVSS Scoring

No CVSS v3 score available

Affected Software
From NVD CPE configuration data

Vendors

Palo Alto Networks

Products

Expedition
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

No references available.

Source: CISA KEV + NVD · Data may lag official sources by up to one minute