CVE-2017-5200

Description

Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on a salt-master via Salts ssh_client.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.262

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in VMware SALT 2016.11.0Windows
Multiple Vulnerabilities are affected in VMware SALT 2016.11.1Windows
Multiple Vulnerabilities are affected in VMware SALT 2016.11.2Windows
Multiple Vulnerabilities are affected in VMware SALT 2015.8.12Windows
Vulnerabilities CVE-2017-5192,CVE-2017-5200 are affected in VMware SALT 2016.3.0Windows
Vulnerabilities CVE-2017-5192,CVE-2017-5200 are affected in VMware SALT 2016.3.1Windows
Vulnerabilities CVE-2017-5192,CVE-2017-5200 are affected in VMware SALT 2016.3.2Windows
Multiple Vulnerabilities are affected in VMware SALT 2016.3.3Windows
Vulnerabilities CVE-2017-5192,CVE-2017-5200 are affected in VMware SALT 2016.3.4Windows
Multiple vulnerabilities are fixed in Python-salt 2015.8.13Windows
Vulnerabilities CVE-2017-5192,CVE-2017-5200 are fixed in Python-salt 2016.11.2Windows
Vulnerabilities CVE-2017-5192,CVE-2017-5200 are fixed in Python-salt 2016.3.5Windows
Multiple vulnerabilities are fixed in Python-salt for linux 2015.8.13Linux
Vulnerabilities CVE-2017-5192,CVE-2017-5200 are fixed in Python-salt for linux 2016.11.2Linux
Vulnerabilities CVE-2017-5192,CVE-2017-5200 are fixed in Python-salt for linux 2016.3.5Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234