Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-4436

Опубликовано: 05 нояб. 2013
Источник: debian
EPSS Низкий

Описание

The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote attackers to have unspecified impact via a man-in-the-middle (MITM) attack.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
saltfixed0.17.1+dfsg-1package

EPSS

Процентиль: 72%
0.00711
Низкий

Связанные уязвимости

ubuntu
больше 12 лет назад

The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote attackers to have unspecified impact via a man-in-the-middle (MITM) attack.

nvd
больше 12 лет назад

The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote attackers to have unspecified impact via a man-in-the-middle (MITM) attack.

CVSS3: 7.5
github
больше 3 лет назад

SaltStack MITM SSH attack in salt-ssh

EPSS

Процентиль: 72%
0.00711
Низкий