Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown

CVE-2024-9463

Disclosure Date: October 09, 2024 (last updated October 16, 2024)
An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.
Attacker Value
Unknown

CVE-2020-1977

Disclosure Date: February 12, 2020 (last updated February 21, 2025)
Insufficient Cross-Site Request Forgery (XSRF) protection on Expedition Migration Tool allows remote unauthenticated attackers to hijack the authentication of administrators and to perform actions on the Expedition Migration Tool. This issue affects Expedition Migration Tool 1.1.51 and earlier versions.
Attacker Value
Unknown

CVE-2019-1567

Disclosure Date: October 29, 2019 (last updated December 06, 2023)
The Expedition Migration tool 1.1.6 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings.
0
Attacker Value
Unknown

CVE-2019-1574

Disclosure Date: April 12, 2019 (last updated December 06, 2023)
Cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition Migration tool 1.1.12 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the Devices View.
0
Attacker Value
Unknown

CVE-2019-1574

Disclosure Date: April 12, 2019 (last updated December 06, 2023)
Cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition Migration tool 1.1.12 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the Devices View.
0
Attacker Value
Unknown

CVE-2019-1567

Disclosure Date: April 09, 2019 (last updated December 06, 2023)
The Expedition Migration tool 1.1.6 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings.
0
Attacker Value
Unknown

CVE-2019-1571

Disclosure Date: March 26, 2019 (last updated November 27, 2024)
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the RADIUS server settings.
0
Attacker Value
Unknown

CVE-2019-1570

Disclosure Date: March 26, 2019 (last updated November 27, 2024)
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the LDAP server settings.
0
Attacker Value
Unknown

CVE-2019-1569

Disclosure Date: March 26, 2019 (last updated November 27, 2024)
The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings for account name of admin user.
0
Attacker Value
Unknown

CVE-2018-10143

Disclosure Date: December 12, 2018 (last updated November 27, 2024)
The Palo Alto Networks Expedition Migration tool 1.0.107 and earlier may allow an unauthenticated attacker with remote access to run system level commands on the device hosting this service/application.
0