Palo Alto Security Updates 09 February 2023

Palo Alto has released security updates to fix multiple vulnerabilities in Cortex XSOAR, and Cortex XDR Agent.

The severity of the addressed vulnerabilities could allow the attacker to obtain information or cause a denial of service on the affected systems.

Sample of the addressed vulnerabilities:

Cortex XSOAR Server Local File Disclosure Vulnerability (CVE-2023-0003):

• CVSS: 6.5

• Attack Vector: Network

• Attack Complexity: Low

• Privileges Required: Low

• User Interaction: None

• Consequences: Obtain Information

Vulnerabilities
  • CVE-2023-0001
  • CVE-2023-0002
  • CVE-2023-0003
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Palo Alto Security Advisory

References