Unvalidated SSH Host Key in Salt (aka SaltStack) 0.17.0 Allows MITM Attack
CVE-2013-4436 · HIGH Severity
AV:N/AC:M/AU:N/C:C/I:C/A:C
The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote attackers to have unspecified impact via a man-in-the-middle (MITM) attack.
Learn more about our Web Application Penetration Testing UK.