CVE-2018-10143Critical

CVE-2018-10143 Remote Code Execution in Expedition Migration Tool

Published
December 11, 2018
Last Modified
December 11, 2018

🔗 CVE IDs covered (1)

📋 Description

A remote code execution vulnerability exists in the Palo Alto Networks Migration Tool (“Expedition”). (Ref # MT-794/ CVE-2018-10143) Successful exploitation of this issue may allow an unauthenticated attacker with remote access to run system level commands on the device hosting this service/application. This issue affects Expedition 1.0.107 and earlier. Note that this issue only impacts the Palo Alto Networks Migration Tool (“Expedition”), a tool available from the Palo Alto Networks Live site. This issue does not affect PAN-OS or any other supported product or service. For more information on Expedition, see: https://live.paloaltonetworks.com/t5/Expedition-Migration-Tool/ct-p/migration_tool.

🎯 Affected products1

  • Expedition

✅ Remediation

Expedition 1.0.108 and later Workarounds and mitigations: N/A

🔗 References (1)