← volver
CVE-2024-5912

Cortex XDR Agent: Improper File Signature Verification Checks

CVSS 6.8 MEDIUMEPSS 0.1%CWE-347
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.8EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch referenciado
Ciclo de vida
10 jul 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to bypass the Cortex XDR agent's executable blocking capabilities and run untrusted executables on the device. This issue can be leveraged to execute untrusted software without being detected or blocked.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/AU:N/R:U/V:C/RE:M/U:Amber

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →