CVE-2025-2184 MEDIUM

CVE-2025-2184: Cortex XDR Broker VM: Secrets Shared Across Multiple Broker VM Images

Vendor Palo Alto Networks
Product Cortex XDR Broker VM
Weakness CWE-1392
Published August 13, 2025
Last update August 13, 2025

CVSS base score

5.3/10
Attack vector Physical
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/AU:Y/R:U/V:C/RE:M/U:Amber

What the vulnerability does

01Description

A credential management flaw in Palo Alto Networks Cortex XDR® Broker VM causes different Broker VM images to share identical default credentials for internal services. Users knowing these default credentials could access internal services on other Broker VM installations. The attacker must have network access to the Broker VM to exploit this issue.

Key dates

02Disclosure timeline

August 13, 2025 CVE published
August 13, 2025 Record updated

Related vulnerabilities

04Related CVE