Impact
The vulnerability is a privilege escalation flaw that allows an authenticated low‑privileged user who can intercept traffic (man‑in‑the‑middle) to execute arbitrary code with root privileges on the Broker VM. This weakness is identified as CWE‑88, which indicates a privilege escalation by bypassing intended access controls. Successful exploitation would grant the attacker full control over the Broker VM, compromising confidentiality, integrity, and availability of the monitoring solution.
Affected Systems
The flaw affects Palo Alto Networks Cortex XDR Broker VM deployments that are running a version prior to 32.0.52. All later releases contain the fix. The documentation does not enumerate specific sub‑versions, so any deployment below the stated version baseline should be considered vulnerable.
Risk and Exploitability
The CVSS score of 4.8 places this vulnerability in the medium severity range, and the EPSS score is not available, meaning there is no current statistical evidence of exploitation. The flaw is not listed in the CISA KEV catalog, but the likely attack vector requires a low‑privileged authenticated user with man‑in‑the‑middle access, so widespread exploitation is currently considered unlikely. Nonetheless, the potential for complete compromise of the Broker VM warrants immediate attention, and the user should apply the vendor’s patch cycle promptly.
OpenCVE Enrichment