PT-2022-12950 · Palo Alto Networks · Cortex Xdr Agent
Robert Mccallum
·
Published
2022-01-12
·
Updated
2022-01-19
·
CVE-2022-0013
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Palo Alto Networks Cortex XDR agent versions earlier than 5.0.12
Palo Alto Networks Cortex XDR agent versions earlier than 6.1.9
Palo Alto Networks Cortex XDR agent versions earlier than 7.2.4
Palo Alto Networks Cortex XDR agent versions earlier than 7.3.2
Description
A file information exposure issue exists in the Palo Alto Networks Cortex XDR agent, allowing a local attacker to read the contents of arbitrary files on the system with elevated privileges when generating a support file.
Recommendations
For versions earlier than 5.0.12, update to version 5.0.12 or later.
For versions earlier than 6.1.9, update to version 6.1.9 or later.
For versions earlier than 7.2.4, update to version 7.2.4 or later.
For versions earlier than 7.3.2, update to version 7.3.2 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cortex Xdr Agent