Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:47658
HistoryJun 20, 2024 - 6:12 a.m.

Privilege Escalation

2024-06-2006:12:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
2
salt software
vulnerability
privilege escalation

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.1

Confidence

Low

EPSS

0.006

Percentile

79.5%

salt is vulnerable to Privilege Escalation. The vulnerability is caused due to the dropping of group privileges by the salt master, which makes it easier for remote attackers to gain privileges.

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.1

Confidence

Low

EPSS

0.006

Percentile

79.5%