CVE-2025-4234
Cortex XDR Microsoft 365 Defender Pack: Cleartext Exposure of Credentials
Vexday Risk Score
8Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 2.4EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
12 set 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
A problem with the Palo Alto Networks Cortex XDR Microsoft 365 Defender Pack can result in exposure of user credentials in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This means that these credentials are exposed to recipients of the application logs.
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/AU:N/R:U/V:D/RE:M/U:Amber
Produtos afetados
Palo Alto Networks · Cortex XDR Microsoft 365 Defender PackQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →