CVE Vulnerabilities

CVE-2024-9466

Insertion of Sensitive Information into Log File

Published: Oct 09, 2024 | Modified: Oct 17, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated using those credentials.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
Expedition Paloaltonetworks 1.2.0 (including) 1.2.96 (excluding)

Potential Mitigations

References