CVE Vulnerabilities

CVE-2016-3176

Improper Authentication

Published: Jan 31, 2017 | Modified: Feb 07, 2017
CVSS 3.x
5.6
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Salt Saltstack * 2015.5.9 (including)
Salt Saltstack 2015.8.0 (including) 2015.8.0 (including)
Salt Saltstack 2015.8.1 (including) 2015.8.1 (including)
Salt Saltstack 2015.8.2 (including) 2015.8.2 (including)
Salt Saltstack 2015.8.3 (including) 2015.8.3 (including)
Salt Saltstack 2015.8.4 (including) 2015.8.4 (including)
Salt Saltstack 2015.8.5 (including) 2015.8.5 (including)
Salt Saltstack 2015.8.7 (including) 2015.8.7 (including)

Potential Mitigations

References