Vulnerability Database

322,732

Total vulnerabilities in the database

CVE-2021-3051

An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enables an unauthenticated network-based attacker with specific knowledge of the Cortex XSOAR instance to access protected resources and perform unauthorized actions on the Cortex XSOAR server. This issue impacts: Cortex XSOAR 5.5.0 builds earlier than 1578677; Cortex XSOAR 6.0.2 builds earlier than 1576452; Cortex XSOAR 6.1.0 builds earlier than 1578663; Cortex XSOAR 6.2.0 builds earlier than 1578666. All Cortex XSOAR instances hosted by Palo Alto Networks are protected from this vulnerability; no additional action is required for these instances.

  • Published: Sep 8, 2021
  • Updated: Nov 16, 2025
  • CVE: CVE-2021-3051
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 8.1
  • AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: Medium
  • Score: 6.8
  • AV:N/AC:M/Au:N/C:P/I:P/A:P

CWEs:

Software From Fixed in
paloaltonetworks / cortex_xsoar 5.5.0-94592 5.5.0-94592.x
paloaltonetworks / cortex_xsoar 5.5.0-78518 5.5.0-78518.x
paloaltonetworks / cortex_xsoar 5.5.0-75211 5.5.0-75211.x
paloaltonetworks / cortex_xsoar 5.5.0-73387 5.5.0-73387.x
paloaltonetworks / cortex_xsoar 5.5.0-70066 5.5.0-70066.x
paloaltonetworks / cortex_xsoar 6.0.2-97682 6.0.2-97682.x
paloaltonetworks / cortex_xsoar 6.0.2-94597 6.0.2-94597.x
paloaltonetworks / cortex_xsoar 6.0.2-93351 6.0.2-93351.x
paloaltonetworks / cortex_xsoar 6.0.2-90947 6.0.2-90947.x
paloaltonetworks / cortex_xsoar 6.2.0 6.2.0.x
paloaltonetworks / cortex_xsoar 6.1.0-1016923 6.1.0-1016923.x
paloaltonetworks / cortex_xsoar 6.1.0-1031903 6.1.0-1031903.x
paloaltonetworks / cortex_xsoar 6.1.0-848144 6.1.0-848144.x
paloaltonetworks / cortex_xsoar 6.1.0-1077664 6.1.0-1077664.x
paloaltonetworks / cortex_xsoar 6.1.0 6.1.0.x
paloaltonetworks / cortex_xsoar 6.2.0-1271082 6.2.0-1271082.x
paloaltonetworks / cortex_xsoar 6.2.0-1321594 6.2.0-1321594.x
paloaltonetworks / cortex_xsoar 6.2.0-1473927 6.2.0-1473927.x
paloaltonetworks / cortex_xsoar 6.1.0-1209934 6.1.0-1209934.x
paloaltonetworks / cortex_xsoar 6.1.0-1271079 6.1.0-1271079.x
paloaltonetworks / cortex_xsoar 6.0.2 6.0.2.x
paloaltonetworks / cortex_xsoar 5.5.0 5.5.0.x