Improper protection of alternate path in Cortex XDR Broker VM - CVE-2025-0113

 

Improper protection of alternate path in Cortex XDR Broker VM - CVE-2025-0113

Published: February 18, 2025


Vulnerability identifier: #VU104027
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-0113
CWE-ID: CWE-424
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to VM docker containers.

The vulnerability exists due to an error within the network isolation mechanism. A remote non-authenticated attacker can gain unauthorized access to Docker containers from the host network used by Broker VM and read files sent for analysis and logs transmitted by the Cortex XDR Agent to the Cortex XDR server.


Affected software

Cortex XDR Broker VM

How to mitigate CVE-2025-0113

Install updates from vendor's website.

Cortex XDR Broker VM - update to 26.0.116

External References

Related Security Bulletins