CVE-2025-0132
Cortex XDR Broker VM: Unauthenticated User Can Disable Internal Services
Severity
Medium 6.9
CVSS 4.0
Exploited
Not listed
EPSS
0.004
37.9th percentile
Discovered by
Third party
Vendor-published field
Published
May 14, 2025
Assigned by palo_alto
Description
A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal services on the Broker VM. The attacker must have network access to the Broker VM to exploit this issue.
Weakness: CWE-306
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Palo Alto Networks | Cortex XDR | Endpoint / EDR | cna-assigner |
Vendor-reported products (1)
- Palo Alto Networks · Cortex XDR Broker VM
Credit
Bartosz Chałek
Vendor remediation
This issue is fixed in Cortex XDR Broker VM 26.0.119, and all later Cortex XDR Broker VM versions. * If you enabled automatic upgrades for Broker VM, then no action is required at this time. * If you did not enable automatic upgrades, then we recommend that you do so for Broker VM to ensure that you always have the latest security patches installed in your software.