Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2013-4436
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2013-4436

2022-10-0316:14:57
Debian Security Bug Tracker
security-tracker.debian.org
13
saltstack
ssh host key
validation

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.002

Percentile

61.6%

The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote attackers to have unspecified impact via a man-in-the-middle (MITM) attack.

OSVersionArchitecturePackageVersionFilename
Debian11allsalt< 0.17.1+dfsg-1salt_0.17.1+dfsg-1_all.deb

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.002

Percentile

61.6%