QID 376470

Date Published: 2022-03-15

QID 376470: Palo Alto Networks Cortex XDR Agent Exceptional condition Denial of Service (DoS) Vulnerability (CPATR-9871)

An improper handling of exceptional conditions vulnerability allows a local authenticated Windows user to create files in the software's internal program directory in the Palo Alto Networks Cortex XDR agent

Affected versions:
Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.10;
Cortex XDR agent 6.1 versions earlier than Cortex XDR agent 6.1.7;
Cortex XDR agent 7.0 versions earlier than Cortex XDR agent 7.0.3;
Cortex XDR agent 7.1 versions earlier than Cortex XDR agent 7.1.2;

QID Detection Logic (Authenticated) :
This checks for vulnerable version of CyveraConsole.exe file.

Successful exploitation could lead to exceptional condition denial-of-service (DoS)

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    Vendor has released updates to fix the issue. Please refer to vendor advisory CVE-2020-2020 for more information.
    Vendor References

    CVEs related to QID 376470

    Software Advisories
    Advisory ID Software Component Link
    CVE-2020-2020 URL Logo security.paloaltonetworks.com/CVE-2020-2020