CVE-2016-3176

MEDIUM

Salt < 2015.5.9 - Authentication Bypass

Title source: rule

Description

Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.

Scores

CVSS v3 5.6
EPSS 0.0017
EPSS Percentile 37.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-287
Status draft

Affected Products (9)

saltstack/salt < 2015.5.9
saltstack/salt
saltstack/salt
saltstack/salt
saltstack/salt
saltstack/salt
saltstack/salt
saltstack/salt
pypi/salt < 2015.5.10PyPI

Timeline

Published Jan 31, 2017
Tracked Since Feb 18, 2026