PT-2022-12950 · Palo Alto Networks · Cortex Xdr Agent
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Palo Alto Networks Cortex XDR agent versions earlier than 5.0.12
Palo Alto Networks Cortex XDR agent versions earlier than 6.1.9
Palo Alto Networks Cortex XDR agent versions earlier than 7.2.4
Palo Alto Networks Cortex XDR agent versions earlier than 7.3.2
Description
A file information exposure issue exists in the Palo Alto Networks Cortex XDR agent, allowing a local attacker to read the contents of arbitrary files on the system with elevated privileges when generating a support file.
Recommendations
For versions earlier than 5.0.12, update to version 5.0.12 or later.
For versions earlier than 6.1.9, update to version 6.1.9 or later.
For versions earlier than 7.2.4, update to version 7.2.4 or later.
For versions earlier than 7.3.2, update to version 7.3.2 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cortex Xdr Agent