vendor:
Expedition Migration Tool
by:
paragonsec @ Critical Start
8.8
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: Expedition Migration Tool
Affected Version From: 1.0.106
Affected Version To: 1.0.106
Patch Exists: YES
Related CWE: 2018-10142
CPE: a:palo_alto_networks:expedition_migration_tool:1.0.106
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2018
PaloAlto Networks Expedition Migration Tool 1.0.106 – Information Disclosure
An information disclosure vulnerability exists in PaloAlto Networks Expedition Migration Tool 1.0.106 and prior versions. An unauthenticated attacker can send a specially crafted request to the vulnerable server to disclose sensitive information from the server.
Mitigation:
Upgrade to version 1.0.107 or later.