Cyber Resilience

CVE-2024-8690

Paloaltonetworks Cortex Xdr Agent 7.9.102

Published
11 September 2024
Modified
15 October 2024
Patch / advisory
CVSS Score v4 5.6
Click a component to see what it means
Raw vectorCVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:M/U:Amber
EPSS Score 0.0019 9th percentile
Risk Priority 21 floored blend · peak EPSS

Summary

CVE-2024-8690 is a medium-severity Expected Behavior Violation (CWE-440) vulnerability in Paloaltonetworks Cortex Xdr Agent. Its CVSS base score is 5.6 (Medium).

Operationally, ranked at the 9th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to SA-11 (Developer Testing and Evaluation) and SI-6 (Security and Privacy Function Verification) — see the control section below for these in your framework.

EU & UK References

Vulnerability Data

A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows administrator privileges to disable the agent. This issue may be leveraged by malware to disable the Cortex XDR…

more

agent and then to perform malicious activity.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-0001Same product: Microsoft Windows
CVE-2024-9469Same product: Microsoft Windows
CVE-2026-0232Same product: Microsoft Windows
CVE-2023-0002Same product: Microsoft Windows
CVE-2023-3280Same product: Microsoft Windows
CVE-2026-0278Same product: Microsoft Windows
CVE-2026-0233Same product: Microsoft Windows
CVE-2024-5907Same product: Paloaltonetworks Cortex Xdr Agent
CVE-2024-5909Same product: Paloaltonetworks Cortex Xdr Agent
CVE-2026-0247Same product: Microsoft Windows

Affected Assets

paloaltonetworks
cortex xdr agent
7.9.102

Mitigating Controls

Mitigating Controls (NIST 800-53 r5) AI

Developer testing and evaluation directly checks whether implemented functions match their specifications.

Security function verification confirms that functions operate according to their defined expected behavior.

Requiring a documented security architecture and design reduces the chance that implementation deviates from intended behavior.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 full match
prevents

Secure SDLC practices directly enforce specification compliance and catch expected-behavior violations during development.

ID.IM-02 partial match
prevents

Security testing and exercises help discover behavior deviations before deployment.

ID.RA-01 partial match
prevents

Vulnerability identification can surface spec-violating flaws, while eliminating the weakness reduces some vulnerability backlog.

PR.PS-02 partial match
prevents

Routine software maintenance and patching can remediate discovered specification violations.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

finds

Security testing in development and acceptance validates that functions behave as specified.

prevents

Secure development life cycle mandates verification against specifications, directly reducing expected-behavior violations.

prevents

Application security requirements explicitly define expected behavior that must be met.

prevents

Secure coding practices enforce adherence to functional specifications during implementation.

finds

Change management can catch specification deviations introduced by modifications.

none

Documented operating procedures reduce the chance that functions deviate from intended behavior.

References