7.5
CVSSv2

CVE-2018-15751

Published: 24/10/2018 Updated: 20/08/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SaltStack Salt prior to 2017.7.8 and 2018.3.x prior to 2018.3.3 allow remote malicious users to bypass authentication and execute arbitrary commands via salt-api(netapi).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

saltstack salt

Vendor Advisories

Debian Bug report logs - #913475 salt: CVE-2018-15751: remote authentication bypass in salt-api(netapi) allows to execute arbitrary commands Package: src:salt; Maintainer for src:salt is Debian Salt Team <pkg-salt-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 11 Nov 20 ...
SaltStack Salt before 201778 and 20183x before 201833 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi) ...