CVE-2013-2056
published 2013-07-31CVE-2013-2056: The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5.3, 5.4, and 5.5 does not properly check client "authenticity," which allows…
PriorityP431medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.37%
81.8th percentile
The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5.3, 5.4, and 5.5 does not properly check client "authenticity," which allows remote attackers to obtain channel content by skipping the initial authentication call.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | satellite | — | — |
| redhat | satellite | — | — |
| redhat | satellite | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p9rr-x8fh-7586: The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5
ghsa_unreviewed·2022-05-13
CVE-2013-2056 [MEDIUM] CWE-287 GHSA-p9rr-x8fh-7586: The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5
The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5.3, 5.4, and 5.5 does not properly check client "authenticity," which allows remote attackers to obtain channel content by skipping the initial authentication call.
Red Hat
CVE-2013-2056: The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5
vendor_redhat·2013-07-31·CVSS 5.0
CVE-2013-2056 [MEDIUM] CWE-306 CVE-2013-2056: The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5
The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5.3, 5.4, and 5.5 does not properly check client "authenticity," which allows remote attackers to obtain channel content by skipping the initial authentication call.
A flaw was found in Red Hat Network Satellite. The Inter-Satellite Sync (ISS) operation, which synchronizes data between satellites, does not properly verify the authenticity of clients. This allows remote attackers to bypass the initial authentication process and obtain sensitive channel content. This vulnerability leads to unauthorized information disclosure.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applic
No detection rules found.
No public exploits indexed.
2013-07-31
Published