CVE-2022-0031
Cortex XSOAR: Local Privilege Escalation (PE) Vulnerability in Cortex XSOAR Engine
Severity Score
6.7
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with elevated privileges.
Una vulnerabilidad de Escalada de Privilegios (PE) locales en el software del motor Cortex XSOAR de Palo Alto Networks que se ejecuta en un Sistema Operativo Linux permite a un atacante local con acceso de shell al motor, ejecutar programas con privilegios elevados.
*Credits:
Palo Alto Networks thanks Olivier Caillault for discovering and reporting this issue.
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-12-28 CVE Reserved
- 2022-11-09 CVE Published
- 2024-06-01 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-345: Insufficient Verification of Data Authenticity
CAPEC
- CAPEC-233: Privilege Escalation
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://security.paloaltonetworks.com/CVE-2022-0031 | 2022-11-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Paloaltonetworks Search vendor "Paloaltonetworks" | Cortex Xsoar Search vendor "Paloaltonetworks" for product "Cortex Xsoar" | 6.5.0 Search vendor "Paloaltonetworks" for product "Cortex Xsoar" and version "6.5.0" | 2102531 |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|
Paloaltonetworks Search vendor "Paloaltonetworks" | Cortex Xsoar Search vendor "Paloaltonetworks" for product "Cortex Xsoar" | 6.5.0 Search vendor "Paloaltonetworks" for product "Cortex Xsoar" and version "6.5.0" | 2410815 |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|
Paloaltonetworks Search vendor "Paloaltonetworks" | Cortex Xsoar Search vendor "Paloaltonetworks" for product "Cortex Xsoar" | 6.5.0 Search vendor "Paloaltonetworks" for product "Cortex Xsoar" and version "6.5.0" | 2583817 |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|
Paloaltonetworks Search vendor "Paloaltonetworks" | Cortex Xsoar Search vendor "Paloaltonetworks" for product "Cortex Xsoar" | 6.6.0 Search vendor "Paloaltonetworks" for product "Cortex Xsoar" and version "6.6.0" | 2585049 |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|
Paloaltonetworks Search vendor "Paloaltonetworks" | Cortex Xsoar Search vendor "Paloaltonetworks" for product "Cortex Xsoar" | 6.6.0 Search vendor "Paloaltonetworks" for product "Cortex Xsoar" and version "6.6.0" | 2889656 |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|
Paloaltonetworks Search vendor "Paloaltonetworks" | Cortex Xsoar Search vendor "Paloaltonetworks" for product "Cortex Xsoar" | 6.6.0 Search vendor "Paloaltonetworks" for product "Cortex Xsoar" and version "6.6.0" | 3049220 |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|
Paloaltonetworks Search vendor "Paloaltonetworks" | Cortex Xsoar Search vendor "Paloaltonetworks" for product "Cortex Xsoar" | 6.6.0 Search vendor "Paloaltonetworks" for product "Cortex Xsoar" and version "6.6.0" | 3124193 |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|
Paloaltonetworks Search vendor "Paloaltonetworks" | Cortex Xsoar Search vendor "Paloaltonetworks" for product "Cortex Xsoar" | 6.8.0 Search vendor "Paloaltonetworks" for product "Cortex Xsoar" and version "6.8.0" | 3261002 |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|