PatchSiren cyber security CVE debrief
CVE-2024-5910 Palo Alto Networks CVE debrief
CVE-2024-5910 is a missing authentication vulnerability in Palo Alto Networks Expedition. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-11-07, which means it is treated as an exploited issue and should be handled as a high-priority defensive item. The supplied corpus does not include a CVSS score, so remediation urgency should be driven by the KEV listing and vendor guidance.
- Vendor
- Palo Alto Networks
- Product
- Expedition
- CVSS
- CRITICAL 9.3
- CISA KEV
- Listed
- Original CVE published
- 2024-11-07
- Original CVE updated
- 2024-11-07
- Advisory published
- 2024-11-07
- Advisory updated
- 2024-11-07
Who should care
Administrators and security teams responsible for Palo Alto Networks Expedition deployments, especially teams managing exposed or business-critical instances, as well as incident response teams tracking CISA KEV items.
Technical summary
The vulnerability is described as a missing authentication issue in Palo Alto Networks Expedition. The CISA KEV record identifies Palo Alto Networks as the vendor, Expedition as the product, and sets a remediation due date of 2024-11-28. No CVSS score is provided in the supplied source data.
Defensive priority
Urgent. Because CVE-2024-5910 is listed in CISA’s Known Exploited Vulnerabilities catalog, it should be prioritized ahead of routine maintenance. Follow vendor mitigations promptly; if mitigations are unavailable, CISA’s guidance is to discontinue use of the product.
Recommended defensive actions
- Identify all Palo Alto Networks Expedition instances in your environment, including test and forgotten deployments.
- Apply mitigations per Palo Alto Networks’ vendor instructions referenced by CISA as soon as possible.
- If mitigations are unavailable or cannot be applied safely, discontinue use of the product per CISA guidance.
- Prioritize remediation before the CISA KEV due date of 2024-11-28.
- Review relevant access and administrative activity on affected systems for signs of unauthorized use.
- Validate that asset inventory, patch tracking, and exception handling are updated to reflect the KEV status.
Evidence notes
Source evidence is limited to official records and the CISA KEV entry. The CISA KEV JSON lists Palo Alto Networks as the vendor, Expedition as the product, and includes dateAdded 2024-11-07 and dueDate 2024-11-28, with the remediation note: apply mitigations per vendor instructions or discontinue use if mitigations are unavailable. The CVE.org and NVD links confirm the record exists. The supplied corpus does not include a CVSS score or additional technical detail beyond the missing authentication description.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-5910 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-5910
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-5910 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-5910
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.