CVE 2.4 LOW

Cortex XDR Microsoft 365 Defender Pack: Cleartext Exposure of Credentials_CVE-2025-4234

2.4 / 10
LOW
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/AU:N/R:U/V:D/RE:M/U:Amber

Description

A problem with the Palo Alto Networks Cortex XDR Microsoft 365 Defender Pack can result in exposure of user credentials in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This means that these credentials are exposed to recipients of the application logs.

Basic Information

ID CVE-2025-4234
Source palo_alto
Published Sep 12, 2025 at 17:18
Modified Sep 12, 2025 at 17:30

Affected Product

Vendor Palo Alto Networks
Product Cortex XDR Microsoft 365 Defender Pack
Version 4.6.0
Affected Versions Palo Alto Networks Cortex XDR Microsoft 365 Defender Pack 4.6.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.