SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-3144

In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration.

CRITICAL 9.1EPSS 5.24%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (5.24%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.)

CVSS 3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS
5.24% probability · 92th percentile
CISA KEV
Not listed
Weakness
CWE-613
Affected
saltstack/salt · fedoraproject/fedora · debian/debian linux
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.