CVE-2013-4480
published 2013-11-18CVE-2013-4480: Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which allows remote attackers to…
PriorityP340high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.13%
80.1th percentile
Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which allows remote attackers to create administrator accounts.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | network_satellite | <= 5.6 | — |
| redhat | satellite | <= 5.6 | — |
| redhat | satellite_with_embedded_oracle | — | — |
| redhat | satellite_with_embedded_oracle | — | — |
| redhat | satellite_with_embedded_oracle | — | — |
| redhat | satellite_with_embedded_oracle | — | — |
| suse | linux_enterprise | — | — |
| suse | manager | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6g3j-mch3-9577: Red Hat Satellite 5
ghsa_unreviewed·2022-05-13
CVE-2013-4480 [HIGH] CWE-668 GHSA-6g3j-mch3-9577: Red Hat Satellite 5
Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which allows remote attackers to create administrator accounts.
Red Hat
Satellite: Interface to create the initial administrator user remains open after installation
vendor_redhat·2013-11-12·CVSS 7.5
CVE-2013-4480 [HIGH] CWE-862 Satellite: Interface to create the initial administrator user remains open after installation
Satellite: Interface to create the initial administrator user remains open after installation
Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which allows remote attackers to create administrator accounts.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00009.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1513.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1514.htmlhttps://access.redhat.com/site/articles/539283https://bugzilla.redhat.com/show_bug.cgi?id=1024614http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00009.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1513.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1514.htmlhttps://access.redhat.com/site/articles/539283https://bugzilla.redhat.com/show_bug.cgi?id=1024614
2013-11-18
Published