CVE-2022-0013: Cortex XDR Agent: File Information Exposure Vulnerability When Generating Support File
A file information exposure vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker to read the contents of arbitrary files on the system with elevated privileges when generating a support file. This issue impacts: Cortex XDR agent 5.0 versions earlier than Cortex XDR agent 5.0.12; Cortex XDR agent 6.1 versions earlier than Cortex XDR agent 6.1.9; Cortex XDR agent 7.2 versions earlier than Cortex XDR agent 7.2.4; Cortex XDR agent 7.3 versions earlier than Cortex XDR agent 7.3.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-0013?
CVE-2022-0013 is a file information exposure vulnerability in the Palo Alto Networks Cortex XDR agent that allows a local attacker to read the contents of arbitrary files on the system with elevated privileges when generating a support file.
Which versions of Cortex XDR agent are affected by CVE-2022-0013?
Cortex XDR agent 5.0 versions earlier than 5.0.12, Cortex XDR agent 6.1 versions earlier than 6.1.9, Cortex XDR agent 7.2 versions earlier than 7.2.4, and Cortex XDR agent 7.3 versions earlier than 7.3.2 are affected by CVE-2022-0013.
How severe is CVE-2022-0013?
CVE-2022-0013 has a severity rating of 5.5, which is considered medium.
What is the Common Weakness Enumeration (CWE) ID of CVE-2022-0013?
CVE-2022-0013 is associated with CWE-200 and CWE-538.
Where can I find more information about CVE-2022-0013?
More information about CVE-2022-0013 can be found at https://security.paloaltonetworks.com/CVE-2022-0013.