Lucene search

K
cvelistRedhatCVELIST:CVE-2013-4436
HistoryNov 05, 2013 - 6:00 p.m.

CVE-2013-4436

2013-11-0518:00:00
redhat
www.cve.org
7
default configuration
saltstack 0.17.0
ssh host key
mitm attack

AI Score

6.8

Confidence

Low

EPSS

0.002

Percentile

61.6%

The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote attackers to have unspecified impact via a man-in-the-middle (MITM) attack.

AI Score

6.8

Confidence

Low

EPSS

0.002

Percentile

61.6%