QID 376472

Date Published: 2022-03-16

QID 376472: Palo Alto Networks Cortex XDR Agent Multiple Vulnerabilities (CPATR-13408,CPATR-13480,CPATR-12633)

Multiple vulnerabilities impacting Palo Alto Networks Cortex XDR agent

Affected versions:
Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12;
Cortex XDR agent 6.1 versions earlier than Cortex XDR agent 6.1.9;
Cortex XDR agent 7.2 versions earlier than Cortex XDR agent 7.2.4;
Cortex XDR agent 7.3 versions earlier than Cortex XDR agent 7.3.2;

QID Detection Logic (Authenticated) :
This checks for vulnerable version of CyveraConsole.exe file.

Successful exploitation could lead to exceptional condition denial-of-service (DoS) and privilege escalation

  • CVSS V3 rated as High - 7.3 severity.
  • CVSS V2 rated as High - 6.9 severity.
  • Solution
    Vendor has released updates to fix the issue. Please refer to vendor advisory CVE-2022-0012 CVE-2022-0013and CVE-2022-0014 for more information.
    Vendor References

    CVEs related to QID 376472

    Software Advisories
    Advisory ID Software Component Link
    CPATR-13480 URL Logo security.paloaltonetworks.com/CVE-2022-0013
    CPATR-12633 URL Logo security.paloaltonetworks.com/CVE-2022-0014
    CPATR-13408 URL Logo security.paloaltonetworks.com/CVE-2022-0012