vendor:
Expedition
by:
ByteHunter
6.1
CVSS
HIGH
Admin Account Takeover
798
CWE
Product Name: Expedition
Affected Version From: 1.2
Affected Version To: 1.2.91
Patch Exists: NO
Related CWE: CVE-2024-5910
CPE: a:paloaltonetworks:expedition:1.2.90.1
Platforms Tested:
2024
Palo Alto Networks Expedition 1.2.90.1 – Admin Account Takeover
The Palo Alto Networks Expedition version 1.2.90.1 is vulnerable to an admin account takeover. By exploiting this vulnerability, an attacker can reset the admin password to 'paloalto' and gain access to the admin panel.
Mitigation:
It is recommended to update the Palo Alto Networks Expedition to version 1.2.92 or higher to mitigate this vulnerability.