Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-62349

Опубликовано: 30 янв. 2026
Источник: nvd
CVSS3: 6.2
EPSS Низкий

Описание

Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer authentication/security features by using an older request payload format, enabling minion impersonation and circumventing protections introduced in response to prior issues.

EPSS

Процентиль: 5%
0.00021
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 6.2
ubuntu
8 дней назад

Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer authentication/security features by using an older request payload format, enabling minion impersonation and circumventing protections introduced in response to prior issues.

CVSS3: 6.2
debian
8 дней назад

Salt contains an authentication protocol version downgrade weakness th ...

CVSS3: 6.2
github
8 дней назад

Salt Authentication Protocol Version Downgrade Allows Minion Impersonation

suse-cvrf
около 2 месяцев назад

Security update for salt

suse-cvrf
около 2 месяцев назад

Security update for salt

EPSS

Процентиль: 5%
0.00021
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-287