PoC Index

CVE-2024-9465

KEVCRITICAL 9.2EPSS 99.6%

An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.

CVSS v4.0
9.2 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:H/U:Amber
CVSS v3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS
99.63% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2024-11-14
Nuclei
high · CWE-89
Published
2024-10-09
Updated
2025-10-21

Proof-of-concept exploits (3)

Nuclei templates (1)

Exploit collections (1)

References

Related