Skip to main content

Palo Alto Networks Patches Unauthenticated Command Execution Flaw in Cortex XSOAR


Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

Palo Alto Networks has patched multiple vulnerabilities, including ones rated high severity, in several products.

 

August 15, 2024 By Eduard Kovacs

 

Palo Alto Networks

Palo Alto Networks on Wednesday announced patches for vulnerabilities found in several of its products, including flaws that have been assigned a ‘high severity’ rating.

The most important vulnerability is CVE-2024-5914, described as a high-severity command injection issue affecting the company’s Cortex XSOAR security orchestration, automation and response (SOAR) product.   

Specifically, the flaw affects the product’s CommonScripts Pack and allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container.

However, Palo Alto Networks noted that only certain configurations are impacted. Patches are being included in versions starting with 1.12.33.

Another advisory with an overall rating of ‘high severity’ describes vulnerabilities in the Prisma Access Browser. The browser is based on Chromium and the cybersecurity giant has now integrated the latest upstream security fixes, which cover over 30 vulnerabilities.

 

>>Full Article<<

0 replies

Be the first to reply!

Reply