CVE-2020-25592

Description

In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
44.938

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in VMware SALT 2016.11.2Windows
Multiple Vulnerabilities are affected in VMware SALT 2016.11.5Windows
Multiple Vulnerabilities are affected in VMware SALT 2016.3.7Windows
Multiple Vulnerabilities are affected in VMware SALT 2015.8.12Windows
Multiple Vulnerabilities are affected in VMware SALT 2016.3.3Windows
Multiple Vulnerabilities are affected in VMware SALT 2016.3.5Windows
Multiple Vulnerabilities are affected in VMware SALT 2017.7.7Windows
Multiple Vulnerabilities are affected in VMware SALT 2015.8.9Windows
Multiple Vulnerabilities are affected in VMware SALT 2016.11.9Windows
Vulnerabilities CVE-2020-16846,CVE-2020-17490,CVE-2020-25592 are affected in VMware SALT 2017.7.3Windows
Vulnerabilities CVE-2020-16846,CVE-2020-17490,CVE-2020-25592 are affected in VMware SALT 2018.3.4Windows
Multiple Vulnerabilities are affected in VMware SALT 2019.2.4Windows
Vulnerabilities CVE-2020-16846,CVE-2020-17490,CVE-2020-25592 are affected in VMware SALT 3000.2Windows
Vulnerabilities CVE-2020-16846,CVE-2020-17490,CVE-2020-25592 are affected in VMware SALT 3001Windows
Multiple vulnerabilities are fixed in Python-salt 2016.3.8Windows
Multiple vulnerabilities are fixed in Python-salt 2015.8.13Windows
Multiple vulnerabilities are fixed in Python-salt 2016.11.10Windows
Multiple vulnerabilities are fixed in Python-salt 2017.7.8Windows
Vulnerabilities CVE-2020-16846,CVE-2020-17490,CVE-2020-25592 are fixed in Python-salt 2018.3.5Windows
Vulnerabilities CVE-2020-16846,CVE-2020-17490,CVE-2020-25592 are fixed in Python-salt 3002.1Windows
Vulnerabilities CVE-2020-25592 are fixed in Python-salt 2019.2.7Windows
Vulnerabilities CVE-2020-25592 are fixed in Python-salt 3000.5Windows
Vulnerabilities CVE-2020-25592 are fixed in Python-salt 3001.3Windows
SUSE-SU-2021:2106-1(SUSE Linux Enterprise Module for Python2 15-SP3 ) python2-distro-1.5.0-3.5.1.noarch.rpmLinux
SUSE-SU-2021:2106-1(SUSE Linux Enterprise Module for Basesystem 15-SP3 ) python3-distro-1.5.0-3.5.1.noarch.rpmLinux
Multiple vulnerabilities are fixed in Python-salt for linux 2016.3.8Linux
Multiple vulnerabilities are fixed in Python-salt for linux 2015.8.13Linux
Multiple vulnerabilities are fixed in Python-salt for linux 2016.11.10Linux
Multiple vulnerabilities are fixed in Python-salt for linux 2017.7.8Linux
Vulnerabilities CVE-2020-16846,CVE-2020-17490,CVE-2020-25592 are fixed in Python-salt for linux 2018.3.5Linux
Vulnerabilities CVE-2020-16846,CVE-2020-17490,CVE-2020-25592 are fixed in Python-salt for linux 3002.1Linux
Vulnerabilities CVE-2020-25592 are fixed in Python-salt for linux 2019.2.7Linux
Vulnerabilities CVE-2020-25592 are fixed in Python-salt for linux 3000.5Linux
Vulnerabilities CVE-2020-25592 are fixed in Python-salt for linux 3001.3Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234