Severity
7.5HIGH
EPSS
0.7%
top 27.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 18
Latest updateMay 13

Description

Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which allows remote attackers to create administrator accounts.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages4 packages

Also affects: Linux Enterprise 11.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6g3j-mch3-9577: Red Hat Satellite 52022-05-13
CVEList
CVE-2013-4480: Red Hat Satellite 52013-11-15

📋Vendor Advisories

1
Red Hat
Satellite: Interface to create the initial administrator user remains open after installation2013-11-12

💬Community

1
Bugzilla
CVE-2013-4480 Satellite: Interface to create the initial administrator user remains open after installation2013-10-30
CVE-2013-4480 (HIGH CVSS 7.5) | Red Hat Satellite 5.6 and earlier d | cvebase.io