CVE-2023-0003

A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
palo_altoCNA
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
VendorProductVersion
paloaltonetworkscortex_xsoar
6.10.0 ≤
𝑥
< 6.10.0.185964
paloaltonetworkscortex_xsoar
6.6.0:2585049
paloaltonetworkscortex_xsoar
6.6.0:2889656
paloaltonetworkscortex_xsoar
6.6.0:3049220
paloaltonetworkscortex_xsoar
6.6.0:3124193
paloaltonetworkscortex_xsoar
6.8.0:176620
paloaltonetworkscortex_xsoar
6.8.0:3261002
paloaltonetworkscortex_xsoar
6.9.0:130766
paloaltonetworkscortex_xsoar
6.9.0:177754
𝑥
= Vulnerable software versions
References