CVE-2017-14696
UnknownEPSS 2.74%
Last modified
CVE-2017-14696 is a vulnerability of currently unknown severity. SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote attackers to cause a denial of service via a crafted authentication request.. EPSS estimates a 2.74% chance of exploitation in the next 30 days.
Description
SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote attackers to cause a denial of service via a crafted authentication request.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Saltstack | Salt | <= 2016.3.7 |
| Saltstack | Salt | 2016.11 |
| Saltstack | Salt | 2016.11.0 |
| Saltstack | Salt | 2016.11.1 |
| Saltstack | Salt | 2016.11.2 |
| Saltstack | Salt | 2016.11.3 |
| Saltstack | Salt | 2016.11.4 |
| Saltstack | Salt | 2016.11.5 |
| Saltstack | Salt | 2016.11.6 |
| Saltstack | Salt | 2016.11.7 |
| Saltstack | Salt | 2017.7.0 |
| Saltstack | Salt | 2017.7.1 |
References
- http://lists.opensuse.org/opensuse-updates/2017-10/msg00073.htmlIssue Tracking, Release Notes, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2017-10/msg00075.htmlIssue Tracking, Release Notes, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1500742Issue Tracking, Release Notes, Third Party Advisory
- https://docs.saltstack.com/en/latest/topics/releases/2016.11.8.htmlIssue Tracking, Release Notes, Vendor Advisory
- https://docs.saltstack.com/en/latest/topics/releases/2016.3.8.htmlIssue Tracking, Release Notes, Vendor Advisory
- https://docs.saltstack.com/en/latest/topics/releases/2017.7.2.htmlIssue Tracking, Release Notes, Vendor Advisory
- https://github.com/saltstack/salt/commit/5f8b5e1a0f23fe0f2be5b3c3e04199b57a53db5bIssue Tracking, Patch, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2017-10/msg00073.htmlIssue Tracking, Release Notes, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2017-10/msg00075.htmlIssue Tracking, Release Notes, Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1500742Issue Tracking, Release Notes, Third Party Advisory
- https://docs.saltstack.com/en/latest/topics/releases/2016.11.8.htmlIssue Tracking, Release Notes, Vendor Advisory
- https://docs.saltstack.com/en/latest/topics/releases/2016.3.8.htmlIssue Tracking, Release Notes, Vendor Advisory
- https://docs.saltstack.com/en/latest/topics/releases/2017.7.2.htmlIssue Tracking, Release Notes, Vendor Advisory
- https://github.com/saltstack/salt/commit/5f8b5e1a0f23fe0f2be5b3c3e04199b57a53db5bIssue Tracking, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-14696?
SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote attackers to cause a denial of service via a crafted authentication request.
How severe is CVE-2017-14696?
Severity scoring for CVE-2017-14696 is pending analysis. The EPSS model estimates a 2.74% probability of exploitation in the next 30 days.
How do I fix CVE-2017-14696?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-14690STDU Viewer 1.6.375 allows attackers to execute arbitrary co…
- CVE-2017-14691STDU Viewer 1.6.375 allows attackers to cause a denial of se…
- CVE-2017-14692STDU Viewer 1.6.375 allows attackers to execute arbitrary co…
- CVE-2017-14693IrfanView 4.44 - 32bit allows attackers to cause a denial of…
- CVE-2017-14694Foxit Reader 8.3.2.25013 and earlier and Foxit PhantomPDF 8.…
- CVE-2017-14695Directory traversal vulnerability in minion id validation in…
- CVE-2017-14698ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D…
- CVE-2017-14699Multiple XML external entity (XXE) vulnerabilities in the Ai…
- CVE-2017-14702ERS Data System 1.8.1.0 allows remote attackers to execute a…9.8
- CVE-2017-14703SQL injection vulnerability in Cash Back Comparison Script 1…
- CVE-2017-14704Multiple unrestricted file upload vulnerabilities in the (1)…
- CVE-2017-14705DenyAll WAF before 6.4.1 allows unauthenticated remote comma…
Are you affected by CVE-2017-14696?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
