{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.1",
    "cveMetadata": {
        "cveId": "CVE-2025-0119",
        "assignerOrgId": "d6c1279f-00f6-4ef7-9217-f89ffe703ec0",
        "state": "PUBLISHED",
        "assignerShortName": "palo_alto",
        "dateReserved": "2024-12-20T23:23:20.523Z",
        "datePublished": "2025-04-11T17:37:54.484Z",
        "dateUpdated": "2025-04-11T19:00:51.084Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "unaffected",
                    "product": "Cortex XDR Broker VM",
                    "vendor": "Palo Alto Networks",
                    "versions": [
                        {
                            "changes": [
                                {
                                    "at": "26.100.3",
                                    "status": "unaffected"
                                }
                            ],
                            "lessThan": "26.100.3",
                            "status": "affected",
                            "version": "1.0.0",
                            "versionType": "custom"
                        }
                    ]
                }
            ],
            "configurations": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "No special configuration is required to be affected by this issue."
                        }
                    ],
                    "value": "No special configuration is required to be affected by this issue."
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Bartosz Chałek"
                },
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Piotr Kozowicz of CERT Team of ING Bank Slaski"
                }
            ],
            "datePublic": "2025-04-09T16:00:00.000Z",
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "A command injection vulnerability&nbsp;in the Palo Alto Networks Cortex XDR® Broker VM&nbsp;allows an authenticated user to execute arbitrary OS commands with root privileges on the host operating system running Broker VM."
                        }
                    ],
                    "value": "A command injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary OS commands with root privileges on the host operating system running Broker VM."
                }
            ],
            "exploits": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "Palo Alto Networks is not aware of any malicious exploitation of this issue."
                        }
                    ],
                    "value": "Palo Alto Networks is not aware of any malicious exploitation of this issue."
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-242",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-242 Code Injection"
                        }
                    ]
                }
            ],
            "metrics": [
                {
                    "cvssV4_0": {
                        "Automatable": "NO",
                        "Recovery": "USER",
                        "Safety": "NOT_DEFINED",
                        "attackComplexity": "LOW",
                        "attackRequirements": "NONE",
                        "attackVector": "LOCAL",
                        "baseScore": 6.3,
                        "baseSeverity": "MEDIUM",
                        "privilegesRequired": "LOW",
                        "providerUrgency": "AMBER",
                        "subAvailabilityImpact": "HIGH",
                        "subConfidentialityImpact": "HIGH",
                        "subIntegrityImpact": "HIGH",
                        "userInteraction": "NONE",
                        "valueDensity": "DIFFUSE",
                        "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/AU:N/R:U/V:D/RE:M/U:Amber",
                        "version": "4.0",
                        "vulnAvailabilityImpact": "LOW",
                        "vulnConfidentialityImpact": "LOW",
                        "vulnIntegrityImpact": "LOW",
                        "vulnerabilityResponseEffort": "MODERATE"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-78",
                            "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "d6c1279f-00f6-4ef7-9217-f89ffe703ec0",
                "shortName": "palo_alto",
                "dateUpdated": "2025-04-11T17:37:54.484Z"
            },
            "references": [
                {
                    "tags": [
                        "vendor-advisory"
                    ],
                    "url": "https://security.paloaltonetworks.com/CVE-2025-0119"
                }
            ],
            "solutions": [
                {
                    "lang": "eng",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "This issue is fixed in Broker VM 26.100.3 and all later Broker VM versions. If you enabled automatic upgrades for Broker VM, then no action is required at this time. If you did not enable automatic upgrades, then we recommend that you do so for Broker VM to ensure that you always have the latest security patches installed in your software."
                        }
                    ],
                    "value": "This issue is fixed in Broker VM 26.100.3 and all later Broker VM versions. If you enabled automatic upgrades for Broker VM, then no action is required at this time. If you did not enable automatic upgrades, then we recommend that you do so for Broker VM to ensure that you always have the latest security patches installed in your software."
                }
            ],
            "source": {
                "defect": [
                    "CRTX-105746",
                    "CRTX-147814"
                ],
                "discovery": "EXTERNAL"
            },
            "timeline": [
                {
                    "lang": "en",
                    "time": "2025-04-09T16:00:00.000Z",
                    "value": "Initial Publication"
                }
            ],
            "title": "Cortex XDR Broker VM: Authenticated Command Injection Vulnerability in Broker VM",
            "workarounds": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "There are no known workarounds or mitigations for this issue."
                        }
                    ],
                    "value": "There are no known workarounds or mitigations for this issue."
                }
            ],
            "x_affectedList": [
                "Cortex XDR Broker VM   26.100.0",
                "Cortex XDR Broker VM   26.100.1",
                "Cortex XDR Broker VM   26.100.2"
            ],
            "x_generator": {
                "engine": "Vulnogram 0.1.0-dev"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2025-04-11T19:00:41.272635Z",
                                "id": "CVE-2025-0119",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-04-11T19:00:51.084Z"
                }
            }
        ]
    }
}