Impact
Unprivileged authenticated users can trigger a live terminal session through the Cortex UI and retrieve or change sensitive configuration settings of the Cortex XDR Broker VM. This exposes confidential information and allows an attacker to alter system behavior, impacting confidentiality and integrity per CWE-497.
Affected Systems
Palo Alto Networks Cortex XDR Broker VM. All versions prior to 30.0.49 are vulnerable; the issue is fixed in version 30.0.49 and later.
Risk and Exploitability
The CVSS score of 5.7 indicates moderate severity. EPSS is below 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting low exploit probability. Exploitation requires network connectivity to the Broker VM and valid authentication credentials. The attacker may then launch a live terminal session via the Cortex UI to view or modify configuration data.
OpenCVE Enrichment