CVE-2024-38823

CWE-2944 documents4 sources
Severity
2.7LOW
EPSS
0.3%
top 49.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 13

Description

Salt's request server is vulnerable to replay attacks when not using a TLS encrypted transport.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:NExploitability: 1.2 | Impact: 1.4

Affected Packages1 packages

CVEListV5vmware/salt3006.x3006.12+1

🔴Vulnerability Details

3
CVEList
CVE-2024-38823 Salt Advisory2025-06-13
GHSA
GHSA-85cw-m46v-23x6: Salt's request server is vulnerable to replay attacks when not using a TLS encrypted transport2025-06-13
OSV
CVE-2024-38823: Salt's request server is vulnerable to replay attacks when not using a TLS encrypted transport2025-06-13
CVE-2024-38823 (LOW CVSS 2.7) | Salt's request server is vulnerable | cvebase.io