PT-2021-18768 · Palo Alto Networks · Cortex Xsoar
Published
2021-09-08
·
Updated
2021-09-17
·
CVE-2021-3051
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cortex XSOAR versions 5.5.0 builds earlier than 1578677
Cortex XSOAR versions 6.0.2 builds earlier than 1576452
Cortex XSOAR versions 6.1.0 builds earlier than 1578663
Cortex XSOAR versions 6.2.0 builds earlier than 1578666
Description
An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication, enabling an unauthenticated network-based attacker with specific knowledge of the Cortex XSOAR instance to access protected resources and perform unauthorized actions on the Cortex XSOAR server.
Recommendations
For Cortex XSOAR versions 5.5.0 builds earlier than 1578677, update to a build 1578677 or later.
For Cortex XSOAR versions 6.0.2 builds earlier than 1576452, update to a build 1576452 or later.
For Cortex XSOAR versions 6.1.0 builds earlier than 1578663, update to a build 1578663 or later.
For Cortex XSOAR versions 6.2.0 builds earlier than 1578666, update to a build 1578666 or later.
As a temporary workaround, consider restricting access to SAML authentication until a patch is available.
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cortex Xsoar