CVE-2024-9465 is a critical SQL injection vulnerability affecting Palo Alto Networks Expedition, allowing unauthenticated attackers to exfiltrate sensitive database contents like password hashes, usernames, and device configurations, and create/read arbitrary files. With a CVSS score of 9.1 (CRITICAL), this vulnerability is easily exploitable over the network with low complexity and no user interaction, leading to complete compromise of confidentiality and integrity. This flaw is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has garnered significant community attention and media coverage, though no public Metasploit or ExploitDB modules are currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.2.0, < 1.2.96CPE matchmatch criteria | cpe:2.3:a:paloaltonetworks:expedition:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Amber
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.