No analysis available yet.
Vendor Solution
This issue is fixed in Cortex XSOAR CommonScripts 1.12.33 and all later versions.
Vendor Workaround
Remove any integration usage of the ScheduleGenericPolling or GenericPollingScheduledTask scripts from the CommonScripts pack.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47046 | A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container. |
| Link | Providers |
|---|---|
| https://security.paloaltonetworks.com/CVE-2024-5914 |
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 20 Aug 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Paloaltonetworks
Paloaltonetworks cortex Xsoar Commonscripts |
|
| CPEs | cpe:2.3:a:paloaltonetworks:cortex_xsoar_commonscripts:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Paloaltonetworks
Paloaltonetworks cortex Xsoar Commonscripts |
|
| Metrics |
cvssV3_1
|
Wed, 14 Aug 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 14 Aug 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container. | |
| Title | Cortex XSOAR: Command Injection in CommonScripts Pack | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2024-08-14T18:17:47.424Z
Reserved: 2024-06-12T15:27:56.494Z
Link: CVE-2024-5914
Updated: 2024-08-14T18:17:42.111Z
Status : Analyzed
Published: 2024-08-14T17:15:18.220
Modified: 2024-08-20T16:22:06.357
Link: CVE-2024-5914
No data.
OpenCVE Enrichment
No data.
EUVD