Логотип exploitDog
bind:CVE-2024-47533
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-47533

Количество 7

Количество 7

ubuntu логотип

CVE-2024-47533

около 1 года назад

Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `''` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2024-47533

около 1 года назад

Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `''` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2024-47533

около 1 года назад

Cobbler, a Linux installation server that allows for rapid setup of ne ...

CVSS3: 9.8
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2024:0382-1

около 1 года назад

Security update for cobbler

EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2024:0370-1

около 1 года назад

Security update for cobbler

EPSS: Средний
github логотип

GHSA-m26c-fcgh-cp6h

около 1 года назад

cobbler allows anyone to connect to cobbler XML-RPC server with known password and make changes

CVSS3: 9.8
EPSS: Средний
fstec логотип

BDU:2024-09952

около 1 года назад

Уязвимость сервера сетевой установки Cobbler, связанная с недостатками процедуры аутентификации, позволяющая нарушителю получить полный доступ к серверу

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-47533

Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `''` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.

CVSS3: 9.8
69%
Средний
около 1 года назад
nvd логотип
CVE-2024-47533

Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior to versions 3.2.3 and 3.3.7. `utils.get_shared_secret()` always returns `-1`, which allows anyone to connect to cobbler XML-RPC as user `''` password `-1` and make any changes. This gives anyone with network access to a cobbler server full control of the server. Versions 3.2.3 and 3.3.7 fix the issue.

CVSS3: 9.8
69%
Средний
около 1 года назад
debian логотип
CVE-2024-47533

Cobbler, a Linux installation server that allows for rapid setup of ne ...

CVSS3: 9.8
69%
Средний
около 1 года назад
suse-cvrf логотип
openSUSE-SU-2024:0382-1

Security update for cobbler

69%
Средний
около 1 года назад
suse-cvrf логотип
openSUSE-SU-2024:0370-1

Security update for cobbler

69%
Средний
около 1 года назад
github логотип
GHSA-m26c-fcgh-cp6h

cobbler allows anyone to connect to cobbler XML-RPC server with known password and make changes

CVSS3: 9.8
69%
Средний
около 1 года назад
fstec логотип
BDU:2024-09952

Уязвимость сервера сетевой установки Cobbler, связанная с недостатками процедуры аутентификации, позволяющая нарушителю получить полный доступ к серверу

CVSS3: 9.8
69%
Средний
около 1 года назад

Уязвимостей на страницу