Alert

Alert 2024-50 Critical Vulnerability in Palo Alto Expedition

Palo Alto Networks has issued a warning about several critical vulnerabilities in its Expedition tool, used to migrate firewall configurations. These vulnerabilities allow attackers to take control of administrative accounts on PAN-OS firewalls, accessing sensitive information such as usernames, cleartext passwords, device configurations, and API keys.

To mitigate these risks, Palo Alto recommends updating Expedition to version 1.2.96 or later and rotating all affected credentials, including usernames, passwords, and API keys. It is also recommended to restrict network access to only authorized users and hosts.

For more information and patches, you can access the official Palo Alto Networks site.