CVE-2017-15136
published 2018-02-27CVE-2017-15136: When registering and activating a new system with Red Hat Satellite 6 if the new systems hostname is then reset to the hostname of a previously registered…
PriorityP49low2.7CVSS 3.0
AVNACLPRHUINSUCNINAL
EPSS
0.98%
58.1th percentile
When registering and activating a new system with Red Hat Satellite 6 if the new systems hostname is then reset to the hostname of a previously registered system the previously registered system will lose access to updates including security updates.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat_inc | satellite_6 | — | — |
| redhat | satellite | — | — |
CVSS provenance
nvdv3.02.7LOWCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_redhat2.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6vg6-5p3g-6rw4: When registering and activating a new system with Red Hat Satellite 6 if the new systems hostname is then reset to the hostname of a previously regist
ghsa_unreviewed·2022-05-13
CVE-2017-15136 [MEDIUM] GHSA-6vg6-5p3g-6rw4: When registering and activating a new system with Red Hat Satellite 6 if the new systems hostname is then reset to the hostname of a previously regist
When registering and activating a new system with Red Hat Satellite 6 if the new systems hostname is then reset to the hostname of a previously registered system the previously registered system will lose access to updates including security updates.
Red Hat
katello: system registration hostname hijacking results in inability to access updates
vendor_redhat·2018-02-27·CVSS 2.7
CVE-2017-15136 [LOW] CWE-20 katello: system registration hostname hijacking results in inability to access updates
katello: system registration hostname hijacking results in inability to access updates
When registering and activating a new system with Red Hat Satellite 6 if the new systems hostname is then reset to the hostname of a previously registered system the previously registered system will lose access to updates including security updates.
When registering a system with Satellite 6 a hostname must be specified. if an additional system is registered with the same hostname, the original system will stop receiving updates from Satellite 6. An attacker with administrative privileges to add systems to a Satellite 6 server could exploit this to prevent other hosts from getting security updates.
Package: katello (Red Hat Satellite 6) - Will not fix
No detection rules found.
No public exploits indexed.
2018-02-27
Published