CVE-2024-5910

CVE Published 2024-07-10
Related CWE(s) CWE-306: Missing Authentication for Critical Function
Related Vendor(s) paloaltonetworks
Related Product(s) expedition
Exploitation Reported (CISA KEV) 2024-11-07
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition.

Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References