CVE-2021-3051: Cortex XSOAR: Authentication Bypass in SAML Authentication
An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enables an unauthenticated network-based attacker with specific knowledge of the Cortex XSOAR instance to access protected resources and perform unauthorized actions on the Cortex XSOAR server. This issue impacts: Cortex XSOAR 5.5.0 builds earlier than 1578677; Cortex XSOAR 6.0.2 builds earlier than 1576452; Cortex XSOAR 6.1.0 builds earlier than 1578663; Cortex XSOAR 6.2.0 builds earlier than 1578666. All Cortex XSOAR instances hosted by Palo Alto Networks are protected from this vulnerability; no additional action is required for these instances.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Palo Alto Networks Cortex XSOARto a version that resolves this vulnerability.Fixed in 5.5.0 build 1578677 - Upgrade
Upgrade
Palo Alto Networks Cortex XSOARto a version that resolves this vulnerability.Fixed in 6.0.2 build 1576452 - Upgrade
Upgrade
Palo Alto Networks Cortex XSOARto a version that resolves this vulnerability.Fixed in 6.1.0 build 1578663 - Upgrade
Upgrade
Palo Alto Networks Cortex XSOARto a version that resolves this vulnerability.Fixed in 6.2.0 build 1578666
Event History
Frequently Asked Questions
What is CVE-2021-3051?
CVE-2021-3051 is an improper verification of cryptographic signature vulnerability in Cortex XSOAR SAML authentication.
What is the severity of CVE-2021-3051?
The severity of CVE-2021-3051 is high, with a CVSS score of 8.1.
Which version of Cortex XSOAR is affected by CVE-2021-3051?
Cortex XSOAR versions 5.5.0 to 6.2.0 are affected by CVE-2021-3051.
How does CVE-2021-3051 impact the system?
CVE-2021-3051 allows an unauthenticated attacker with specific knowledge of the Cortex XSOAR instance to access protected resources and perform unauthorized actions.
Is there a fix available for CVE-2021-3051?
Yes, Palo Alto Networks has released a security advisory with mitigation steps for CVE-2021-3051.