5.5

CVE-2023-3280

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user to disable the agent.

Data is provided by the National Vulnerability Database (NVD)
PaloaltonetworksCortex Xdr Agent Version >= 5.0 <= 5.0.12.22203
   MicrosoftWindows Version-
PaloaltonetworksCortex Xdr Agent SwEdition- Version >= 7.9.0 < 7.9.3
   MicrosoftWindows Version-
PaloaltonetworksCortex Xdr Agent SwEditioncontent_update Version >= 7.9.0 < 7.9.101
   MicrosoftWindows Version-
PaloaltonetworksCortex Xdr Agent Version >= 8.0.0 < 8.0.2
   MicrosoftWindows Version-
PaloaltonetworksCortex Xdr Agent Version7.5.102 SwEditioncontent_update
   MicrosoftWindows Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.08% 0.252
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
psirt@paloaltonetworks.com 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-755 Improper Handling of Exceptional Conditions

The product does not handle or incorrectly handles an exceptional condition.