SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-1583

Escalation of privilege vulnerability in the Palo Alto Networks Twistlock console 19.07.358 and earlier allows a Twistlock user with Operator capabilities to escalate privileges to that of another user.

HIGH 8.0EPSS 1.17%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.17%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Escalation of privilege vulnerability in the Palo Alto Networks Twistlock console 19.07.358 and earlier allows a Twistlock user with Operator capabilities to escalate privileges to that of another user. Active interaction with an affected component is required for the payload to execute on the victim.

CVSS 3.0
8.0 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS
1.17% probability · 66th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
paloaltonetworks/twistlock
Source
psirt@paloaltonetworks.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.