Target Industry

Indiscriminate, opportunistic targeting.

Overview 

A missing authentication flaw in Palo Alto Networks’ Expedition tool is allowing threat actors with network access to take over the administrator account. The Expedition tool is utilised to simplify the migration of firewall configurations to Palo Alto Networks. This critical security flaw has been tracked as CVE-2024-5910 with a CVSS score of 9.3. CVE-2024-5910 was released on 10th July 2024. Palo Alto had released a patch a few days after, but it is still being actively exploited.  

Impact 

This vulnerability impacts all versions of Expedition prior to version 1.2.92, posing a significant security risk to organisations using these affected versions. There is also the additional risk that the vulnerability can be chained with other flaws to gain unauthorised command execution on vulnerable servers. 

Exploitation 

The CVE-2024-5910 vulnerability in Palo Alto Networks’ Expedition tool is exploited by threat actors remotely resetting the administration credentials on internet-exposed Expedition servers. This allows them to take over the administrator account and access sensitive data.  

Additionally, a proof-of-concept exploit demonstrates how this flaw can be chained with another vulnerability (CVE-2024-9464) to execute arbitrary commands on vulnerable servers. This makes the exploitation particularly dangerous, as it can lead to full system compromise. 

Containment, Mitigations & Remediations 

It is highly recommended to upgrade to the latest version immediately. It is also recommended to rotate the following after upgrading: 

  • All Expedition usernames, passwords, and API keys 
  • All firewall usernames, passwords, and API keys 

 Indicators of Compromise
At the time of witing, there are no specific indicators of compromise for the exploitation of the Palo Alto Networks vulnerability (CVE-2024-5910). 

Threat Landscape 

Palo Alto Networks serves over 70,000 organisations in more than 150 countries. While there are no detailed reports on how this vulnerability is being weaponised in real-world attacks, Palo Alto Networks has updated its advisory. They have confirmed that the Cybersecurity and Infrastructure Security Agency (CISA) has found evidence of active exploitation. 

Threat Group 

The specific threat group behind this has not been publicly identified at the time of writing. 

TTPs 

  • TA0029 – Privilege Escalation 
  • TA0031 – Credential Access 
  • T1068 – Exploitation for Privilege Escalation 

Further Information 

https://security.paloaltonetworks.com/CVE-2024-5910 

https://www.heise.de/en/news/CISA-warns-of-four-actively-attacked-security-vulnerabilities-10009292.html
https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-palo-alto-networks-bug-exploited-in-attacks/
https://thehackernews.com/2024/11/cisa-alerts-to-active-exploitation-of.html 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content