CVE-2024-38825
MEDIUMSalt 3006.0rc1-3006.11 and 3007.0-3007.3 - Improper Authentication in PKI Module
Title source: llmDescription
The salt.auth.pki module does not properly authenticate callers. The "password" field contains a public certificate which is validated against a CA certificate by the module. This is not pki authentication, as the caller does not need access to the corresponding private key for the authentication attempt to be accepted.
References (2)
Core 2
Core References
Scores
CVSS v3
6.4
EPSS
0.0012
EPSS Percentile
30.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-287
Status
published
Products (3)
pypi/salt
3006.0rc1 - 3006.12PyPI
VMware/SALT
3006.x - 3006.12
VMware/SALT
3007.x - 3007.4
Published
Jun 13, 2025
Tracked Since
Feb 18, 2026