# CVE-2024-9463

## Summary

- **CVE ID:** CVE-2024-9463
- **Severity:** CRITICAL
- **CVSS Score:** 9.9 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N/AU:N/R:U/V:C/RE:H/U:Amber)
- **CWE:** CWE-78
- **Published:** Oct 9, 2024
- **Last Modified:** Oct 21, 2025

## Description

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

## Affected Products

- Palo Alto Networks — Expedition (1.2.0)

## References

- [CNA](https://security.paloaltonetworks.com/PAN-SA-2024-0010)
- [CISA-ADP](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-9463)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 98.55%
- **EPSS Percentile:** 99.9

## Known Exploited Vulnerabilities (KEV)

- **Date Added:** Nov 14, 2024
- **Due Date:** Dec 5, 2024

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._