A credential management flaw in Palo Alto Networks Cortex XDR® Broker VM causes different Broker VM images to share identical default credentials for internal services. Users knowing these default credentials could access internal services on other Broker VM installations. The attacker must have network access to the Broker VM to exploit this issue.
History

Fri, 15 Aug 2025 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Paloaltonetworks
Paloaltonetworks cortex Xdr Broker Vm
Vendors & Products Paloaltonetworks
Paloaltonetworks cortex Xdr Broker Vm

Thu, 14 Aug 2025 06:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 13 Aug 2025 17:15:00 +0000

Type Values Removed Values Added
Description A credential management flaw in Palo Alto Networks Cortex XDR® Broker VM causes different Broker VM images to share identical default credentials for internal services. Users knowing these default credentials could access internal services on other Broker VM installations. The attacker must have network access to the Broker VM to exploit this issue.
Title Cortex XDR Broker VM: Secrets Shared Across Multiple Broker VM Images
Weaknesses CWE-1392
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/AU:Y/R:U/V:C/RE:M/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published: 2025-08-13T17:05:30.544Z

Updated: 2025-08-13T20:33:40.634Z

Reserved: 2025-03-10T17:56:27.007Z

Link: CVE-2025-2184

cve-icon Vulnrichment

Updated: 2025-08-13T20:33:35.413Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-13T17:15:27.513

Modified: 2025-08-13T17:33:46.673

Link: CVE-2025-2184

cve-icon Redhat

No data.