Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mhj4-9938-5fpw

Опубликовано: 11 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.3
CVSS3: 9.8

Описание

An OS command injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.

An OS command injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.

EPSS

Процентиль: 99%
0.88631
Высокий

6.3 Medium

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 года назад

An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitrary OS commands as the www-data user in Expedition, which results in the disclosure of usernames, cleartext passwords, device configurations, and device API keys for firewalls running PAN-OS software.

CVSS3: 7.4
fstec
около 1 года назад

Уязвимость инструмента миграции конфигурации Palo Alto Networks Expedition, связанная с непринятием мер по нейтрализации специальных элементов, используемых в базовой операционной системе, позволяющая нарушителю выполнять произвольные команды

EPSS

Процентиль: 99%
0.88631
Высокий

6.3 Medium

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-78