Vulnerability Details CVE-2024-5910
Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition.
Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.908
EPSS Ranking 99.6%
CVSS Severity
CVSS v3 Score 9.8
Proposed Action
Palo Alto Networks Expedition contains a missing authentication vulnerability that allows an attacker with network access to takeover an Expedition admin account and potentially access configuration secrets, credentials, and other data.
Ransomware Campaign
Unknown
Products affected by CVE-2024-5910
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.0
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.10
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.11
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.12
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.13
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.14
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.15
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.16.1
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.17
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.18.1
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.19
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.2
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.20
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.21
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.22
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.23
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.24
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.25
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.26
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.28
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.29
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.3
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.30
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.31
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.32
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.33
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.34
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.35
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.36
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.37
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.38
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.39
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.4.2
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.40
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.41
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.42
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.43
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.44
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.45
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.46
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.47
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.48
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.49
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.50
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.51
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.52
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.53
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.54
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.55
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.56
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.57
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.58
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.59
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.6
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.60
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.61
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.62
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.63
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.64
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.65
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.66
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.67
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.68
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.69
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.7
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.70
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.71
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.72
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.73
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.74
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.75
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.76
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.77
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.78
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.79
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.8
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.80
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.81
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.82
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.83
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.84
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.85
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.86
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.87
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.88
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.89
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.9
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.90.1
-
cpe:2.3:a:paloaltonetworks:expedition:1.2.91