Show plain JSON{"id": "CVE-2017-5200", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 9.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C", "authentication": "SINGLE", "integrityImpact": "COMPLETE", "accessComplexity": "LOW", "availabilityImpact": "COMPLETE", "confidentialityImpact": "COMPLETE"}, "acInsufInfo": false, "impactScore": 10.0, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 8.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 8.8, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 2.8}]}, "published": "2017-09-26T14:29:00.597", "references": [{"url": "https://docs.saltstack.com/en/2016.3/topics/releases/2015.8.13.html", "tags": ["Release Notes", "Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "https://docs.saltstack.com/en/2016.3/topics/releases/2016.3.5.html", "tags": ["Release Notes", "Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "https://docs.saltstack.com/en/latest/topics/releases/2016.11.2.html", "tags": ["Release Notes", "Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "https://docs.saltstack.com/en/2016.3/topics/releases/2015.8.13.html", "tags": ["Release Notes", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://docs.saltstack.com/en/2016.3/topics/releases/2016.3.5.html", "tags": ["Release Notes", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://docs.saltstack.com/en/latest/topics/releases/2016.11.2.html", "tags": ["Release Notes", "Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-noinfo"}]}], "descriptions": [{"lang": "en", "value": "Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on a salt-master via Salt's ssh_client."}, {"lang": "es", "value": "salt-api en SaltStack Salt en versiones anteriores a la 2015.8.13, las versiones 2016.3.x anteriores a 2016.3.5 y las versiones 2016.11.x anteriores a 2016.11.2 permite la ejecuci\u00f3n arbitraria de comandos en un salt_master mediante el ssh_client de Salt."}], "lastModified": "2025-04-20T01:37:25.860", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5135EC7D-6FA9-4F57-A282-5F8DA85E8C18", "versionEndIncluding": "2015.8.12"}, {"criteria": "cpe:2.3:a:saltstack:salt:2016.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "45FAF769-AFAC-4235-916C-F6EDA3CD1CA6"}, {"criteria": "cpe:2.3:a:saltstack:salt:2016.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "458E57E7-BF82-4863-B4E4-F39754B6665F"}, {"criteria": "cpe:2.3:a:saltstack:salt:2016.3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5C015342-15C6-4970-9137-10F900962159"}, {"criteria": "cpe:2.3:a:saltstack:salt:2016.3.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2D2868E1-D6E6-4EBC-8330-6603D93C8EB7"}, {"criteria": "cpe:2.3:a:saltstack:salt:2016.3.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BD78645D-A0ED-4B22-982E-A65C016D7384"}, {"criteria": "cpe:2.3:a:saltstack:salt:2016.11.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F5B7EDF4-414F-429A-BD20-0B967737598C"}, {"criteria": "cpe:2.3:a:saltstack:salt:2016.11.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "594339CF-8192-425D-9C8C-AA51342D9477"}, {"criteria": "cpe:2.3:a:saltstack:salt:2016.11.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E54FADCE-5311-4C8A-9527-1623F9AAC69E"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}