Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5vh9-rp4f-879m

Опубликовано: 13 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.3

Описание

A credential management flaw in Palo Alto Networks Cortex XDR® Broker VM causes different Broker VM images to share identical default credentials for internal services. Users knowing these default credentials could access internal services on other Broker VM installations.

The attacker must have network access to the Broker VM to exploit this issue.

A credential management flaw in Palo Alto Networks Cortex XDR® Broker VM causes different Broker VM images to share identical default credentials for internal services. Users knowing these default credentials could access internal services on other Broker VM installations.

The attacker must have network access to the Broker VM to exploit this issue.

EPSS

Процентиль: 5%
0.00026
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-1392

Связанные уязвимости

nvd
около 1 месяца назад

A credential management flaw in Palo Alto Networks Cortex XDR® Broker VM causes different Broker VM images to share identical default credentials for internal services. Users knowing these default credentials could access internal services on other Broker VM installations. The attacker must have network access to the Broker VM to exploit this issue.

CVSS3: 4.3
fstec
6 месяцев назад

Уязвимость компонента Broker VM платформы безопасности Cortex XDR, связанная с использованием учетных данных по умолчанию, позволяющая нарушителю получить доступ к внутренним службам на других виртуальных машинах

EPSS

Процентиль: 5%
0.00026
Низкий

5.3 Medium

CVSS4

Дефекты

CWE-1392