Severity
5.5MEDIUM
EPSS
0.1%
top 71.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 2
Latest updateMay 24

Description

A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of Smart-Proxy. This flaw allows an attacker to gain control of DHCP records from the network. The highest threat from this vulnerability is to system availability.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5red_hat_satelliteRed Hat Satellite 6.9

🔴Vulnerability Details

2
GHSA
GHSA-r449-4m6g-rp77: A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of Smart-Proxy2022-05-24
CVEList
CVE-2020-14335: A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of Smart-Proxy2021-06-02

📋Vendor Advisories

1
Red Hat
foreman: world-readable OMAPI secret through the ISC DHCP server2020-09-07

💬Community

1
Bugzilla
CVE-2020-14335 foreman: world-readable OMAPI secret through the ISC DHCP server2020-07-17
CVE-2020-14335 (MEDIUM CVSS 5.5) | A flaw was found in Red Hat Satelli | cvebase.io