CVE-2024-5910 is a critical missing authentication vulnerability in Palo Alto Networks Expedition, a configuration migration and enrichment tool. This flaw allows an unauthenticated attacker with network access to take over an Expedition admin account, potentially exposing imported configuration secrets and credentials. With a CVSS score of 9.8 (Critical) and an EPSS score indicating high exploitability, this vulnerability poses a severe risk, enabling full compromise of confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, with public exploit code available in Metasploit and ExploitDB, and has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.2.0, < 1.2.92CPE matchmatch criteria | cpe:2.3:a:paloaltonetworks:expedition:*:*:*:*:*:*:*:* | ||
>= 1.2, < 1.2.92CPE match | cpe:2.3:a:paloaltonetworks:expedition:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:M/U:Red
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.