Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-2056

Опубликовано: 31 июл. 2013
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5.3, 5.4, and 5.5 does not properly check client "authenticity," which allows remote attackers to obtain channel content by skipping the initial authentication call.

A flaw was found in Red Hat Network Satellite. The Inter-Satellite Sync (ISS) operation, which synchronizes data between satellites, does not properly verify the authenticity of clients. This allows remote attackers to bypass the initial authentication process and obtain sensitive channel content. This vulnerability leads to unauthorized information disclosure.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Satellite 6satelliteNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-306

EPSS

Процентиль: 82%
0.02367
Низкий

7.5 High

CVSS3

Связанные уязвимости

nvd
около 13 лет назад

The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5.3, 5.4, and 5.5 does not properly check client "authenticity," which allows remote attackers to obtain channel content by skipping the initial authentication call.

github
около 4 лет назад

The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5.3, 5.4, and 5.5 does not properly check client "authenticity," which allows remote attackers to obtain channel content by skipping the initial authentication call.

EPSS

Процентиль: 82%
0.02367
Низкий

7.5 High

CVSS3