LOWCVSS 9.8 · CRITICALCISA KEV
Exploitation ongoing with high activity in latest observed window (1 mentions)
Immediate actions
- Prioritize remediation for paloaltonetworks expedition systems immediately
- Assume compromise if assets are exposed
- Track advisory updates for patch or workaround availability
Recommended action window: Immediate (within 24h)
NVD description
Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition.
Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.