CyberzSOC

Publication detail
← Back to advisories & guidance

2024-083: Palo Alto Cortex XSOAR CommonScripts Critical Vulnerability ↗ source

August 20, 2024 CERT-EU Advisory

Summary

This flaw allows unauthenticated attackers to execute arbitrary commands within the context of an integration container, potentially compromising the system. The vulnerability affects the product’s CommonScripts Pack and is rated as high severity with a CVSS score of 9.0. CVE-2024-5914 is a command injection vulnerability that can be exploited without authentication. It affects specific configurations of Cortex XSOAR’s CommonScripts Pack, allowing remote attackers to execute arbitrary commands. CERT-EU recommends applying the patches included in versions starting with 1.12.33 immediately to mitigate this vulnerability.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-5914 7.0 High Palo Alto Networks Cortex XSOAR CommonScripts A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands with…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.