CVE-2016-3176 Information
Feb 14, 2021
cve
Description
Salt before 2015.5.10 and 2015.8.x before 2015.8.8 when PAM external authentication is enabled allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.
CVSS Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Reference
https://docs.saltstack.com/en/latest/topics/releases/2015.5.10.html https://docs.saltstack.com/en/latest/topics/releases/2015.8.8.html
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
LOW
Base Severity
5.6
Share on: