CVE-2023-0001Medium
CVE-2023-0001 Cortex XDR Agent: Cleartext Exposure of Agent Admin Password
🔗 CVE IDs covered (1)
📋 Description
An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local system administrator to disclose the admin password for the agent in cleartext, which bad actors can then use to execute privileged cytool commands that disable or uninstall the agent.
🎯 Affected products1
- Cortex XDR Agent
✅ Remediation
This issue is fixed in Cortex XDR agent 7.5.101-CE and all later supported Cortex XDR agent versions. (Cortex XDR agent 5.0 is not impacted.) After you upgrade to a fixed version of the Cortex XDR agent, you must change the agent admin password in case it was already disclosed to users. Workarounds and mitigations: There are no known workarounds for this issue.