Target Industry
Indiscriminate, opportunistic targeting.
Overview
A missing authentication flaw in Palo Alto Networks’ Expedition tool is allowing threat actors with network access to take over the administrator account. The Expedition tool is utilised to simplify the migration of firewall configurations to Palo Alto Networks. This critical security flaw has been tracked as CVE-2024-5910 with a CVSS score of 9.3. CVE-2024-5910 was released on 10th July 2024. Palo Alto had released a patch a few days after, but it is still being actively exploited.
Impact
This vulnerability impacts all versions of Expedition prior to version 1.2.92, posing a significant security risk to organisations using these affected versions. There is also the additional risk that the vulnerability can be chained with other flaws to gain unauthorised command execution on vulnerable servers.
Exploitation
The CVE-2024-5910 vulnerability in Palo Alto Networks’ Expedition tool is exploited by threat actors remotely resetting the administration credentials on internet-exposed Expedition servers. This allows them to take over the administrator account and access sensitive data.
Additionally, a proof-of-concept exploit demonstrates how this flaw can be chained with another vulnerability (CVE-2024-9464) to execute arbitrary commands on vulnerable servers. This makes the exploitation particularly dangerous, as it can lead to full system compromise.
Containment, Mitigations & Remediations
It is highly recommended to upgrade to the latest version immediately. It is also recommended to rotate the following after upgrading:
- All Expedition usernames, passwords, and API keys
- All firewall usernames, passwords, and API keys
Indicators of Compromise
At the time of witing, there are no specific indicators of compromise for the exploitation of the Palo Alto Networks vulnerability (CVE-2024-5910).
Threat Landscape
Palo Alto Networks serves over 70,000 organisations in more than 150 countries. While there are no detailed reports on how this vulnerability is being weaponised in real-world attacks, Palo Alto Networks has updated its advisory. They have confirmed that the Cybersecurity and Infrastructure Security Agency (CISA) has found evidence of active exploitation.
Threat Group
The specific threat group behind this has not been publicly identified at the time of writing.
TTPs
- TA0029 – Privilege Escalation
- TA0031 – Credential Access
- TA0002 – Execution
- T1068 – Exploitation for Privilege Escalation
Further Information
https://security.paloaltonetworks.com/CVE-2024-5910
https://www.heise.de/en/news/CISA-warns-of-four-actively-attacked-security-vulnerabilities-10009292.html
https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-palo-alto-networks-bug-exploited-in-attacks/
https://thehackernews.com/2024/11/cisa-alerts-to-active-exploitation-of.html













