CVE-2018-10143Improper Privilege Management in Palo Alto Networks Expedition

Severity
9.8CRITICALNVD
EPSS
28.1%
top 3.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 12
Latest updateMay 13

Description

The Palo Alto Networks Expedition Migration tool 1.0.107 and earlier may allow an unauthenticated attacker with remote access to run system level commands on the device hosting this service/application.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

CVEListV5palo_alto_networks/palo_alto_networks_expeditionExpedition 1.0.107 and earlier

🔴Vulnerability Details

2
GHSA
GHSA-r6rp-496r-7c7f: The Palo Alto Networks Expedition Migration tool 12022-05-13
CVEList
CVE-2018-10143: The Palo Alto Networks Expedition Migration tool 12018-12-12

📋Vendor Advisories

1
Palo Alto
Remote Code Execution in Expedition Migration Tool2018-12-11
CVE-2018-10143 — Improper Privilege Management in Palo | cvebase