CVE-2020-28972Improper Certificate Validation in Salt

Severity
5.9MEDIUMNVD
EPSS
0.5%
top 35.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 27
Latest updateAug 8

Description

In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsphere, and esxi servers (in the vmware.py files) does not always validate the SSL/TLS certificate.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

NVDsaltstack/salt2015.8.112015.8.13+14
PyPIsaltstack/salt2016.3.02016.11.5+22

Also affects: Debian Linux 10.0, 11.0, 9.0, Fedora 32, 33, 34

🔴Vulnerability Details

4
GHSA
SaltStack Salt Improper Certificate Validation2022-05-24
OSV
SaltStack Salt Improper Certificate Validation2022-05-24
CVEList
CVE-2020-28972: In SaltStack Salt before 30022021-02-27
OSV
CVE-2020-28972: In SaltStack Salt before 30022021-02-27

📋Vendor Advisories

2
Ubuntu
Salt vulnerabilities2024-08-08
Red Hat
salt: Authentication to vCenter, vSphere, and ESXi servers does not always validate the SSL/TLS certificate2021-02-25
CVE-2020-28972 — Improper Certificate Validation | cvebase