CVE-2024-9465
- Reference to the description:
- Description:
- An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.
- Last updated date:
- 11/15/2024
Reports
ACTIVELY EXPLOITED
- Type:
- exploitation
- Confidence:
- HIGH
- Date of publishing:
- 11/14/2024
- Reference url to background
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 10/09/2024
- Reference url to background
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 11/15/2024
- Reference url to background
https://www.horizon3.ai/attack-research/palo-alto-expedition-from-n-day-to-full-compromise/
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 12/03/2024
- Reference url to background