Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-9465


An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.


Published

2024-10-09T17:15:20.287

Last Modified

2024-11-15T14:39:34.863

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.1 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-89
  • Type: Primary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application paloaltonetworks expedition < 1.2.96 Yes

References