CVE-2023-0001Medium

CVE-2023-0001 Cortex XDR Agent: Cleartext Exposure of Agent Admin Password

Published
February 8, 2023
Last Modified
February 8, 2023

🔗 CVE IDs covered (1)

📋 Description

An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local system administrator to disclose the admin password for the agent in cleartext, which bad actors can then use to execute privileged cytool commands that disable or uninstall the agent.

🎯 Affected products1

  • Cortex XDR Agent

✅ Remediation

This issue is fixed in Cortex XDR agent 7.5.101-CE and all later supported Cortex XDR agent versions. (Cortex XDR agent 5.0 is not impacted.) After you upgrade to a fixed version of the Cortex XDR agent, you must change the agent admin password in case it was already disclosed to users. Workarounds and mitigations: There are no known workarounds for this issue.

🔗 References (1)