CVE-2022-0031Medium

CVE-2022-0031 Cortex XSOAR: Local Privilege Escalation (PE) Vulnerability in Cortex XSOAR Engine

Published
November 9, 2022
Last Modified
November 19, 2022

🔗 CVE IDs covered (1)

📋 Description

A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with elevated privileges.

🎯 Affected products1

  • Cortex XSOAR

✅ Remediation

This issue is fixed in Cortex XSOAR engine software available in Cortex XSOAR 6.9.0 build 130766 and all later versions of Cortex XSOAR. NOTE: The build numbers for Cortex XSOAR software releases have changed format. Please consider the new format when evaluating version applicability. Cortex XSOAR release documentation is available at the following link: https://docs.paloaltonetworks.com/cortex/cortex-xsoar. Workarounds and mitigations: There are no known workarounds for this issue.

🔗 References (1)