CVE-2023-0001: Cortex XDR Agent: Cleartext Exposure of Agent Admin Password
An information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local system administrator to disclose the admin password for the agent in cleartext, which bad actors can then use to execute privileged cytool commands that disable or uninstall the agent.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-0001?
CVE-2023-0001 is an information exposure vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices, which allows a local system administrator to disclose the admin password in cleartext.
How can this vulnerability be exploited?
This vulnerability can be exploited by a local system administrator who can disclose the admin password and attackers can then use it to execute privileged cytool commands that disable or uninstall the agent.
What is the severity of CVE-2023-0001?
The severity of CVE-2023-0001 is medium with a CVSS score of 6.7.
Which software versions are affected by CVE-2023-0001?
The Palo Alto Networks Cortex XDR agent versions 7.5 and below are affected by CVE-2023-0001.
Is Microsoft Windows affected by this vulnerability?
No, Microsoft Windows is not affected by CVE-2023-0001.
How can I fix CVE-2023-0001?
To fix CVE-2023-0001, it is recommended to update the Palo Alto Networks Cortex XDR agent to a version above 7.5.101.
Where can I find more information about CVE-2023-0001?
You can find more information about CVE-2023-0001 on the Palo Alto Networks Security Advisory page: [https://security.paloaltonetworks.com/CVE-2023-0001]