Palo Alto Networks Expedition
cpe:2.3:a:paloaltonetworks:expedition:*:*:*:*:*:*:*
- < 1.2.101
A command injection vulnerability has been identified in Palo Alto Networks Expedition, specifically in versions prior to 1.2.101. This vulnerability allows an unauthenticated attacker to execute arbitrary operating system commands as the www-data user. The exploitation of this vulnerability leads to the unauthorized disclosure of sensitive information, including usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.
Exploitation of this vulnerability allows for arbitrary OS command execution, with the potential to access and disclose sensitive information such as usernames, cleartext passwords, device configurations, and device API keys for PAN-OS firewalls.
Users can upgrade to Expedition version 1.2.101 or later to address this vulnerability. However, it's important to note that Expedition has reached its End of Life and is no longer supported. Users are advised to transition to the suggested alternatives mentioned in the Expedition End of Life Announcement.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.