Following Palo Alto's announcement of several vulnerabilities in their configuration generation tool Expedition, Horizon released a technical breakdown. In addition to this, watchTowr also released a proof of concept for CVE-2024-9463.
These vulnerabilities are trivial to exploit pose a significant risk to Expedition, whether you expose this to the internet or not.
While this software is not commonly exposed to the internet, a significant risk still remains where an attacker can access the device from the same network as Expedition.