Unvalidated SSH Host Key in Salt (aka SaltStack) 0.17.0 Allows MITM Attack

Unvalidated SSH Host Key in Salt (aka SaltStack) 0.17.0 Allows MITM Attack

CVE-2013-4436 · HIGH Severity

AV:N/AC:M/AU:N/C:C/I:C/A:C

The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote attackers to have unspecified impact via a man-in-the-middle (MITM) attack.

Learn more about our Web Application Penetration Testing UK.