Lucene search

K
nvd[email protected]NVD:CVE-2021-33226
HistoryFeb 17, 2023 - 6:15 p.m.

CVE-2021-33226

2023-02-1718:15:11
CWE-120
web.nvd.nist.gov
5
buffer overflow
saltstack
cve-2021-33226
arbitrary code
status.py file
disputed
eval input

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.003

Percentile

65.8%

Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/status.py file. NOTE: this is disputed by third parties because an attacker cannot influence the eval input

Affected configurations

Nvd
Node
saltstacksaltRange3003
VendorProductVersionCPE
saltstacksalt*cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.003

Percentile

65.8%

Related for NVD:CVE-2021-33226