Lucene search

K
cveMitreCVE-2021-33226
HistoryFeb 17, 2023 - 6:15 p.m.

CVE-2021-33226

2023-02-1718:15:11
CWE-120
mitre
web.nvd.nist.gov
30
cve
2021
33226
buffer overflow
saltstack
security
vulnerability
execution
arbitrary code
nvd

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.003

Percentile

65.8%

Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/status.py file. NOTE: this is disputed by third parties because an attacker cannot influence the eval input

Affected configurations

Nvd
Node
saltstacksaltRange3003
VendorProductVersionCPE
saltstacksalt*cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.003

Percentile

65.8%

Related for CVE-2021-33226