CVE-2021-20256
published 2021-02-23CVE-2021-20256: A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hosts permission…
PriorityP427medium5.3CVSS 3.1
AVLACLPRLUINSUCLILAL
EPSS
0.26%
17.1th percentile
A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | satellite | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Satellite: BMC controller credential leak via API
vendor_redhat·2021-02-19·CVSS 5.3
CVE-2021-20256 [MEDIUM] CWE-200 Satellite: BMC controller credential leak via API
Satellite: BMC controller credential leak via API
A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: Red Hat Satellite is vulnerable to the BMC controller credential leak through the compute host API. Red Hat Product Security has rated this flaw as having a security impact of Moderate. Plea
GHSA
GHSA-7h9m-xcfj-p257: A flaw was found in Red Hat Satellite
ghsa_unreviewed·2022-05-24
CVE-2021-20256 [MEDIUM] CWE-200 GHSA-7h9m-xcfj-p257: A flaw was found in Red Hat Satellite
A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-02-23
Published