8.1
CVSSv3

CVE-2016-1866

Published: 12/04/2016 Updated: 30/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Salt 2015.8.x prior to 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle malicious users to execute arbitrary code by inserting packets into the minion-master data stream.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

saltstack salt 2015.8.3

saltstack salt 2015.8.1

saltstack salt 2015.8.2

saltstack salt 2015.8.0

opensuse leap 42.1

Vendor Advisories

Salt 20158x before 201584 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream ...