CVE-2024-9463CISA KEVEPSS p99.9%

CVE-2024-9463Palo Alto Networks Expedition OS Command Injection Vulnerability

Palo Alto Networks / Expedition

Description

Palo Alto Networks Expedition contains an OS command injection vulnerability that allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

Scoring

EPSS98.39% probability of exploitation · percentile 99.9% · 2026-06-18T12:00:27Z

CISA KEV entry

Added to KEV: 2024-11-14

(incoming)1

TypeTargetConfidenceTier
KEVEntryPalo Alto Networks Expedition OS Command Injection Vulnerabilitykev-cve-2024-94630%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Palo Alto Networks Expedition SQL Injection Vulnerability
CVE
CVE-2025-0107
CVE
Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability
CVE
Palo Alto Networks PAN-OS Command Injection Vulnerability
CVE
Palo Alto Networks Expedition Missing Authentication Vulnerability
CVE
CVE-2025-0103
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.