PT-2021-18768 · Palo Alto Networks · Cortex Xsoar

Published

2021-09-08

·

Updated

2021-09-17

·

CVE-2021-3051

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cortex XSOAR versions 5.5.0 builds earlier than 1578677 Cortex XSOAR versions 6.0.2 builds earlier than 1576452 Cortex XSOAR versions 6.1.0 builds earlier than 1578663 Cortex XSOAR versions 6.2.0 builds earlier than 1578666
Description An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication, enabling an unauthenticated network-based attacker with specific knowledge of the Cortex XSOAR instance to access protected resources and perform unauthorized actions on the Cortex XSOAR server.
Recommendations For Cortex XSOAR versions 5.5.0 builds earlier than 1578677, update to a build 1578677 or later. For Cortex XSOAR versions 6.0.2 builds earlier than 1576452, update to a build 1576452 or later. For Cortex XSOAR versions 6.1.0 builds earlier than 1578663, update to a build 1578663 or later. For Cortex XSOAR versions 6.2.0 builds earlier than 1578666, update to a build 1578666 or later. As a temporary workaround, consider restricting access to SAML authentication until a patch is available.

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-3051

Affected Products

Cortex Xsoar