CVE-2025-0103

An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. This vulnerability also enables attackers to create and read arbitrary files on the Expedition system.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:paloaltonetworks:expedition:*:*:*:*:*:*:*:*

History

23 Jan 2026, 22:03

Type Values Removed Values Added
CPE cpe:2.3:a:paloaltonetworks:expedition:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
Summary
  • (es) Una vulnerabilidad de inyección SQL en Palo Alto Networks Expedition permite a un atacante autenticado revelar el contenido de la base de datos de Expedition, como hashes de contraseñas, nombres de usuario, configuraciones de dispositivos y claves API de dispositivos. Esta vulnerabilidad también permite a los atacantes crear y leer archivos arbitrarios en el sistema Expedition.
First Time Paloaltonetworks
Paloaltonetworks expedition
References () https://security.paloaltonetworks.com/PAN-SA-2025-0001 - () https://security.paloaltonetworks.com/PAN-SA-2025-0001 - Vendor Advisory

11 Jan 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-11 03:15

Updated : 2026-01-23 22:03


NVD link : CVE-2025-0103

Mitre link : CVE-2025-0103

CVE.ORG link : CVE-2025-0103


JSON object : View

Products Affected

paloaltonetworks

  • expedition
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')