CVE-2024-9463Disclosure(paloaltonetworks / expedition)

LOWCVSS 7.5 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for paloaltonetworks expedition systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-12-05. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • expedition

Threat summary

  • Active exploitation appears in 1 classified signals
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-03-30); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
expedition

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-30: 1Mentions · 2026-03-31: 1Mentions · 2026-08-21: 1Mentions · 2026-10-05: 1Active Exploitation · 2026-08-21: 1Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 103-3003-3108-2110-05
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Active Exploitation
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-301
Disclosure1
2026-03-311
General1
2026-08-211
Active Exploitation1
Full discourse4 posts
  • Patrick Roland@DeusLogica
    General

    🔴 EPSS 94.0% | Almost certainly exploitation | medium confidence CVE-2024-9463 (EPSS 94.00%) Palo Alto Networks Expedition OS command injection allows unauthenticated attacker to run arbitrary OS commands as root. Highest risk of all CVEs by exploitation likelihood Source: http://FIRST.org EPSS | Reliability: B Link: https://nvd.nist.gov/vuln/detail/CVE-2024-9463 #EPSS #threatintel #CVE #cybersecurity

    Post summary

    The tweet highlights CVE-2024-9463 as a command injection vulnerability with a high EPSS score, noting potential for exploitation, but provides no PoC, exploitation report, or patch details.

    1000055
    311 followersView on X
  • Patrick Roland@DeusLogica
    Disclosure

    Timestamp: 2026-03-30T11:11:47.241588 Type: HIGH_EPSS Severity: CRITICAL Confidence: MEDIUM Source Reliability: B Title: CVE-2024-9463 (EPSS 94.00%) ## Draft Post 🔴 EPSS 94.0% | Almost certainly exploitation | medium confidence CVE-2024-9463 (EPSS 94.00%) An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expe Highest risk of all CVEs by exploitation likelihood Source: http://FIRST.org EPSS | Reliability: B Link: https://nvd.nist.gov/vuln/detail/CVE-2024-9463 #EPSS #threatintel #CVE #cybersecurity ## CTI Metadata - Confidence Level: MEDIUM - Source Reliability: B - Calibrated Language: medium confidence

    Post summary

    The post announces a high‑EPSS OS command injection flaw in Palo Alto Networks Expedition, highlighting its potential severity, but does not provide any PoC, exploit code, patch, or evidence of active exploitation.

    1000052
    307 followersView on X
  • SHELLCODE@sh3ll_c0d3

    ⚡ CVE-2024-5910 + CVE-2024-9463: Chaining an unauthenticated admin reset with command injection delivers root RCE in Palo Alto Expedition. Read Blog: https://sh3llc0d3.com/blog/palo-alto-networks-expedition-migration-tool-zero-day-chain-from-unauthenticated-admin-reset-to-root-os-command-injection/ #sh3llc0d3 #shellcode #Hacktober #ZeroDay

    0000051
    116 followersView on X
  • Netconverter@Netconverterai
    Active Exploitation

    CISA later added multiple Expedition vulnerabilities to its Known Exploited Vulnerabilities catalog, including CVE-2024-5910, CVE-2024-9463 and CVE-2024-9465. https://t.co/Zn3wjOeHPU

    Post summary

    The tweet notes that CISA added CVE‑2024‑5910, CVE‑2024‑9463, and CVE‑2024‑9465 to its Known Exploited Vulnerabilities catalog, indicating these vulnerabilities are being actively exploited in the wild.

    0000030
    5 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppaloaltonetworksexpedition---

Explore more