CVE-2021-3051

An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enables an unauthenticated network-based attacker with specific knowledge of the Cortex XSOAR instance to access protected resources and perform unauthorized actions on the Cortex XSOAR server. This issue impacts: Cortex XSOAR 5.5.0 builds earlier than 1578677; Cortex XSOAR 6.0.2 builds earlier than 1576452; Cortex XSOAR 6.1.0 builds earlier than 1578663; Cortex XSOAR 6.2.0 builds earlier than 1578666. All Cortex XSOAR instances hosted by Palo Alto Networks are protected from this vulnerability; no additional action is required for these instances.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
palo_altoCNA
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
VendorProductVersion
paloaltonetworkscortex_xsoar
5.5.0
paloaltonetworkscortex_xsoar
5.5.0:70066
paloaltonetworkscortex_xsoar
5.5.0:73387
paloaltonetworkscortex_xsoar
5.5.0:75211
paloaltonetworkscortex_xsoar
5.5.0:78518
paloaltonetworkscortex_xsoar
5.5.0:94592
paloaltonetworkscortex_xsoar
6.0.2
paloaltonetworkscortex_xsoar
6.0.2:90947
paloaltonetworkscortex_xsoar
6.0.2:93351
paloaltonetworkscortex_xsoar
6.0.2:94597
paloaltonetworkscortex_xsoar
6.0.2:97682
paloaltonetworkscortex_xsoar
6.1.0
paloaltonetworkscortex_xsoar
6.1.0:1016923
paloaltonetworkscortex_xsoar
6.1.0:1031903
paloaltonetworkscortex_xsoar
6.1.0:1077664
paloaltonetworkscortex_xsoar
6.1.0:1209934
paloaltonetworkscortex_xsoar
6.1.0:1271079
paloaltonetworkscortex_xsoar
6.1.0:848144
paloaltonetworkscortex_xsoar
6.2.0
paloaltonetworkscortex_xsoar
6.2.0:1271082
paloaltonetworkscortex_xsoar
6.2.0:1321594
paloaltonetworkscortex_xsoar
6.2.0:1473927
𝑥
= Vulnerable software versions