Security Advisory

CVE-2023-0001

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-02-08 17:20:20
Last updated 2024-08-02 04:54:32
Assigner palo_alto
State PUBLISHED

Description

An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local system administrator to disclose the admin password for the agent in cleartext, which bad actors can then use to execute privileged cytool commands that disable or uninstall the agent.