CVE Vulnerabilities

CVE-2021-3051

Improper Verification of Cryptographic Signature

Published: Sep 08, 2021 | Modified: Sep 17, 2021
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enables an unauthenticated network-based attacker with specific knowledge of the Cortex XSOAR instance to access protected resources and perform unauthorized actions on the Cortex XSOAR server. This issue impacts: Cortex XSOAR 5.5.0 builds earlier than 1578677; Cortex XSOAR 6.0.2 builds earlier than 1576452; Cortex XSOAR 6.1.0 builds earlier than 1578663; Cortex XSOAR 6.2.0 builds earlier than 1578666. All Cortex XSOAR instances hosted by Palo Alto Networks are protected from this vulnerability; no additional action is required for these instances.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Cortex_xsoar Paloaltonetworks 5.5.0 (including) 5.5.0 (including)
Cortex_xsoar Paloaltonetworks 5.5.0-70066 (including) 5.5.0-70066 (including)
Cortex_xsoar Paloaltonetworks 5.5.0-73387 (including) 5.5.0-73387 (including)
Cortex_xsoar Paloaltonetworks 5.5.0-75211 (including) 5.5.0-75211 (including)
Cortex_xsoar Paloaltonetworks 5.5.0-78518 (including) 5.5.0-78518 (including)
Cortex_xsoar Paloaltonetworks 5.5.0-94592 (including) 5.5.0-94592 (including)
Cortex_xsoar Paloaltonetworks 6.0.2 (including) 6.0.2 (including)
Cortex_xsoar Paloaltonetworks 6.0.2-90947 (including) 6.0.2-90947 (including)
Cortex_xsoar Paloaltonetworks 6.0.2-93351 (including) 6.0.2-93351 (including)
Cortex_xsoar Paloaltonetworks 6.0.2-94597 (including) 6.0.2-94597 (including)
Cortex_xsoar Paloaltonetworks 6.0.2-97682 (including) 6.0.2-97682 (including)
Cortex_xsoar Paloaltonetworks 6.1.0 (including) 6.1.0 (including)
Cortex_xsoar Paloaltonetworks 6.1.0-1016923 (including) 6.1.0-1016923 (including)
Cortex_xsoar Paloaltonetworks 6.1.0-1031903 (including) 6.1.0-1031903 (including)
Cortex_xsoar Paloaltonetworks 6.1.0-1077664 (including) 6.1.0-1077664 (including)
Cortex_xsoar Paloaltonetworks 6.1.0-1209934 (including) 6.1.0-1209934 (including)
Cortex_xsoar Paloaltonetworks 6.1.0-1271079 (including) 6.1.0-1271079 (including)
Cortex_xsoar Paloaltonetworks 6.1.0-848144 (including) 6.1.0-848144 (including)
Cortex_xsoar Paloaltonetworks 6.2.0 (including) 6.2.0 (including)
Cortex_xsoar Paloaltonetworks 6.2.0-1271082 (including) 6.2.0-1271082 (including)
Cortex_xsoar Paloaltonetworks 6.2.0-1321594 (including) 6.2.0-1321594 (including)
Cortex_xsoar Paloaltonetworks 6.2.0-1473927 (including) 6.2.0-1473927 (including)

References