CyberRota Analysis
AI-GeneratedIn FireAMP versions prior to 2.1.15, users with permissions to edit, create, or run playbooks in Splunk SOAR can exploit a misclassification of the add listitem action as read-only, allowing unauthorized modifications to file lists. This vulnerability poses a risk of unauthorized changes that could compromise data integrity within playbooks. Organizations utilizing affected versions of FireAMP should prioritize remediation to mitigate potential security risks associated with unauthorized access and modifications.
Original NVD Description
In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the add listitem action in a Safe Mode playbook while that action is listed as read-only, which could allow for unauthorized changes to file lists. The vulnerability is possible because the FireAMP connector action manifest classifies the add listitem action as read-only even though the action updates file lists. For more information see Manage settings for a playbook in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-cloud/build-playbooks/manage-playbooks-and-playbook-settings/manage-settings-for-a-playbook-in-splunk-soar-cloud) in the Splunk documentation.