CVE-2021-3049 - CVE House
Back to Database
Status published Low CVE-2021-3049

Cortex XSOAR: Improper Authorization of Incident Investigations Vulnerability

Vulnerability Description

An improper authorization vulnerability in the Palo Alto Networks Cortex XSOAR server enables an authenticated network-based attacker with investigation read permissions to download files from incident investigations of which they are aware but are not a part of. This issue impacts: All Cortex XSOAR 5.5.0 builds; Cortex XSOAR 6.1.0 builds earlier than 12099345. This issue does not impact Cortex XSOAR 6.2.0 versions.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-3049

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Palo Alto Networks would like to thank CAGIP for discovering and reporting this issue.

Affected Vendor

Palo Alto Networks

View all reports →

Affected Software

Cortex XSOAR
Vulnerable Versions:
5.5.0 all, 6.2.0 all, 6.1.0

Timeline

Official Publish: September 8th, 2021
Last Modified: September 16th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N

Weaknesses (CWE)