9
CVSSv2

CVE-2017-5200

Published: 26/09/2017 Updated: 03/10/2019
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

Salt-api in SaltStack Salt prior to 2015.8.13, 2016.3.x prior to 2016.3.5, and 2016.11.x prior to 2016.11.2 allows arbitrary command execution on a salt-master via Salt's ssh_client.

Vulnerable Product Search on Vulmon Subscribe to Product

saltstack salt 2016.11.0

saltstack salt 2016.3.4

saltstack salt 2016.11.2

saltstack salt 2016.3.0

saltstack salt 2016.3.1

saltstack salt 2016.3.2

saltstack salt 2016.11.1

saltstack salt 2016.3.3

saltstack salt

Vendor Advisories

Salt-api in SaltStack Salt before 2015813, 20163x before 201635, and 201611x before 2016112 allows arbitrary command execution on a salt-master via Salt's ssh_client ...
Salt-api allows arbitrary command execution on a salt-master via Salt's ssh_client Users of Salt-API and salt-ssh could execute a command on the salt master via a hole when both systems were enabled ...