Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-1502 | An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to delete arbitrary files accessible to the www-data user on the host filesystem. |
Solution
No solution given by the vendor.
Workaround
Ensure that all network access to Expedition is restricted to only authorized users, hosts, and networks. If you are not actively using Expedition, make sure that your Expedition software is shut down.
| Link | Providers |
|---|---|
| https://security.paloaltonetworks.com/PAN-SA-2025-0001 |
|
Sat, 24 Jan 2026 07:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Paloaltonetworks
Paloaltonetworks expedition |
|
| CPEs | cpe:2.3:a:paloaltonetworks:expedition:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Paloaltonetworks
Paloaltonetworks expedition |
|
| Metrics |
cvssV3_1
|
Tue, 14 Jan 2025 05:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 11 Jan 2025 12:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to delete arbitrary files accessible to the www-data user on the host filesystem. | |
| Title | Expedition: Arbitrary File Deletion Vulnerability | |
| Weaknesses | CWE-73 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2025-01-13T19:50:31.391Z
Reserved: 2024-12-20T23:23:06.874Z
Link: CVE-2025-0105
Updated: 2025-01-13T19:48:52.264Z
Status : Analyzed
Published: 2025-01-11T03:15:22.317
Modified: 2026-01-23T21:56:51.683
Link: CVE-2025-0105
No data.
OpenCVE Enrichment
No data.
EUVD