VendorsPalo Alto Networksexpeditionany version
Vulnerabilities

Palo Alto Networks Expedition any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2024-9463
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
Published 2024-10-09 · Analyzed
9.9KEVEPSS 0.985
CVE-2024-5910
Expedition: Missing Authentication Leads to Admin Account Takeover
Published 2024-07-10 · Analyzed
9.8KEV1 PoCEPSS 0.918
CVE-2025-0107
Expedition: OS Command Injection Vulnerability
Published 2025-01-11 · Analyzed
9.8EPSS 0.785
CVE-2024-9464
Expedition: Authenticated OS Command Injection Vulnerability Leads to Firewall Admin Credential Disclosure
Published 2024-10-09 · Modified
9.3EPSS 0.826
CVE-2024-9465
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
Published 2024-10-09 · Analyzed
9.2KEVEPSS 0.996
CVE-2025-0103
Expedition: SQL Injection Vulnerability
Published 2025-01-11 · Analyzed
9.2EPSS 0.006
CVE-2025-0105
Expedition: Arbitrary File Deletion Vulnerability
Published 2025-01-11 · Analyzed
9.1EPSS 0.133
CVE-2024-9466
Expedition: Cleartext Storage of Information Leads to Firewall Admin Credential Disclosure
Published 2024-10-09 · Modified
8.2EPSS 0.136
CVE-2024-9467
Expedition: Reflected Cross-Site Scripting Vulnerability Leads to Expedition Session Disclosure
Published 2024-10-09 · Analyzed
7.0EPSS 0.007
CVE-2025-0104
Expedition: Cross-Site Scripting (XSS) Vulnerability
Published 2025-01-11 · Analyzed
7.0EPSS 0.004
CVE-2025-0106
Expedition: Wildcard Expansion Vulnerability
Published 2025-01-11 · Analyzed
6.9EPSS 0.005
CVE-2019-1569
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings for account name of admin user.
Published 2019-03-26 · Modified
4.8EPSS 0.011
CVE-2019-1570
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the LDAP server settings.
Published 2019-03-26 · Modified
4.8EPSS 0.011
CVE-2019-1571
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the RADIUS server settings.
Published 2019-03-26 · Modified
4.8EPSS 0.011