CVE-2016-3176

MEDIUM

Salt < 2015.5.10 and 2015.8.x < 2015.8.8 - Authentication Bypass via PAM Service Manipulation

Title source: llm
STIX 2.1

Description

Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_confirm
https://docs.saltstack.com/en/latest/topics/releases/2015.8.8.html
Release Notes, Vendor Advisory x_refsource_confirm
https://docs.saltstack.com/en/latest/topics/releases/2015.5.10.html

Scores

CVSS v3 5.6
EPSS 0.0087
EPSS Percentile 54.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-287
Status published
Products (9)
pypi/salt 0 - 2015.5.10PyPI
saltstack/salt 2015.8.0
saltstack/salt 2015.8.1
saltstack/salt 2015.8.2
saltstack/salt 2015.8.3
saltstack/salt 2015.8.4
saltstack/salt 2015.8.5
saltstack/salt 2015.8.7
saltstack/salt < 2015.5.9
Published Jan 31, 2017
Tracked Since Feb 18, 2026