A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with elevated privileges.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cortex_xsoar | Paloaltonetworks | 6.5.0-2102531 (including) | 6.5.0-2102531 (including) |
Cortex_xsoar | Paloaltonetworks | 6.5.0-2410815 (including) | 6.5.0-2410815 (including) |
Cortex_xsoar | Paloaltonetworks | 6.5.0-2583817 (including) | 6.5.0-2583817 (including) |
Cortex_xsoar | Paloaltonetworks | 6.6.0-2585049 (including) | 6.6.0-2585049 (including) |
Cortex_xsoar | Paloaltonetworks | 6.6.0-2889656 (including) | 6.6.0-2889656 (including) |
Cortex_xsoar | Paloaltonetworks | 6.6.0-3049220 (including) | 6.6.0-3049220 (including) |
Cortex_xsoar | Paloaltonetworks | 6.6.0-3124193 (including) | 6.6.0-3124193 (including) |
Cortex_xsoar | Paloaltonetworks | 6.8.0-3261002 (including) | 6.8.0-3261002 (including) |