A command injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary OS commands with root privileges on the host operating system running Broker VM.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-10809 A command injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary OS commands with root privileges on the host operating system running Broker VM.
Fixes

Solution

No solution given by the vendor.


Workaround

There are no known workarounds or mitigations for this issue.

History

Fri, 11 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Apr 2025 17:45:00 +0000

Type Values Removed Values Added
Description A command injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary OS commands with root privileges on the host operating system running Broker VM.
Title Cortex XDR Broker VM: Authenticated Command Injection Vulnerability in Broker VM
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/AU:N/R:U/V:D/RE:M/U:Amber'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2025-04-11T19:00:51.084Z

Reserved: 2024-12-20T23:23:20.523Z

Link: CVE-2025-0119

cve-icon Vulnrichment

Updated: 2025-04-11T19:00:45.983Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-11T18:15:38.463

Modified: 2025-04-15T18:39:43.697

Link: CVE-2025-0119

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses