CVE-2013-0173: Medium severity theforeman foreman vulnerability
Published May 8, 2014
·Updated
Foreman before 1.1 uses a salt of "foreman" to hash root passwords, which makes it easier for attackers to guess the password via a brute force attack.
Affected Software
1 affected component
theforeman foreman<=1.0
Event History
May 8, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-0173?
CVE-2013-0173 is considered a medium severity vulnerability due to its potential for brute force attacks against root passwords.
2
How do I fix CVE-2013-0173?
To fix CVE-2013-0173, upgrade to Foreman version 1.1 or later, which improves password hashing mechanisms.
3
What versions of Foreman are affected by CVE-2013-0173?
Versions of Foreman prior to 1.1, specifically all versions up to and including 1.0, are affected by CVE-2013-0173.
4
What type of attack is facilitated by CVE-2013-0173?
CVE-2013-0173 facilitates brute force attacks, making it easier for attackers to guess root passwords.
5
Is there a workaround for CVE-2013-0173?
There are no specific workarounds for CVE-2013-0173; the recommended action is to upgrade to a fixed version.