RULE(RULE ID:338733)

Rule General Information
Release Date: 2025-03-11
Rule Name: Palo Alto Networks Expedition restoreAdmin.php Unauthenticated Admin Password Reset Vulnerability (CVE-2024-5910)
Severity:
CVE ID:
Rule Protection Details
Description: Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to Expedition.Note: Expedition is a tool aiding in configuration migration, tuning, and enrichment. Configuration secrets, credentials, and other data imported into Expedition is at risk due to this issue.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: https://security.paloaltonetworks.com/CVE-2024-5910
https://security.paloaltonetworks.com/CVE-2024-5910
https://www.horizon3.ai/attack-research/palo-alto-expedition-from-n-day-to-full-compromise
Solutions
Please refer to announcements or patches release by the vendor: https://security.paloaltonetworks.com/CVE-2024-5910