CVE-2022-0031: Cortex XSOAR: Local Privilege Escalation (PE) Vulnerability in Cortex XSOAR Engine
A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with elevated privileges.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-0031?
CVE-2022-0031 is a local privilege escalation vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system.
How does CVE-2022-0031 impact Palo Alto Networks Cortex XSOAR?
CVE-2022-0031 allows a local attacker with shell access to the engine to execute programs with elevated privileges, potentially leading to unauthorized actions on the system.
Which versions of Palo Alto Networks Cortex XSOAR are affected by CVE-2022-0031?
Palo Alto Networks Cortex XSOAR versions 6.5.0-2102531, 6.5.0-2410815, 6.5.0-2583817, 6.6.0-2585049, 6.6.0-2889656, 6.6.0-3049220, 6.6.0-3124193, and 6.8.0-3261002 are affected by CVE-2022-0031.
What is the severity of CVE-2022-0031?
CVE-2022-0031 has a severity rating of 6.7 (medium).
Is the Linux operating system vulnerable to CVE-2022-0031?
No, the Linux operating system itself is not vulnerable to CVE-2022-0031.