← Back

CVE-2021-3051

nvd nist
Published: Sep 8, 2021Modified: Jun 17, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enables an unauthenticated network-based attacker with specific knowledge of the Cortex XSOAR instance to access protected resources and perform unauthorized actions on the Cortex XSOAR server. This issue impacts: Cortex XSOAR 5.5.0 builds earlier than 1578677; Cortex XSOAR 6.0.2 builds earlier than 1576452; Cortex XSOAR 6.1.0 builds earlier than 1578663; Cortex XSOAR 6.2.0 builds earlier than 1578666. All Cortex XSOAR instances hosted by Palo Alto Networks are protected from this vulnerability; no additional action is required for these instances.

Affected (22)

Cortex Xsoar
Configuration A
22 vulnerable
Vulnerable SoftwareAffected Versions
Paloaltonetworks
Version 5.5.0
Version 5.5.0 70066
Version 5.5.0 73387
Version 5.5.0 75211
Version 5.5.0 78518
Version 5.5.0 94592
Version 6.0.2
Version 6.0.2 90947
Version 6.0.2 93351
Version 6.0.2 94597
Version 6.0.2 97682
Version 6.1.0
Version 6.1.0 1016923
Version 6.1.0 1031903
Version 6.1.0 1077664
Version 6.1.0 1209934
Version 6.1.0 1271079
Version 6.1.0 848144
Version 6.2.0
Version 6.2.0 1271082
Version 6.2.0 1321594
Version 6.2.0 1473927

References (2)

Source: psirt@paloaltonetworks.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.