CVE-2024-9465
CRITICALAn SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device…
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Description
An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.
Affected Products
expeditionpaloaltonetworksResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
An SQL injection vulnerability in Palo Alto Networks Expedition allows a…
An SQL injection vulnerability in Palo Alto Networks Expedition allows a…
An SQL injection vulnerability in Palo Alto Networks Expedition allows a…
An SQL injection vulnerability in Palo Alto Networks Expedition allows a…
Frequently Asked Questions
Is CVE-2024-9465 in your stack?
O3 detects CVE-2024-9465 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.