CVE-2013-4480: High severity red hat satellite vulnerability
It was found that the web interface provided by Red Hat Satellite to create the initial administrator user was not disabled after the initial user was created. A remote attacker could use this flaw to create an administrator user with credentials they specify. This user could then be used to assume control of the Satellite server.
Other sources
Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which allows remote attackers to create administrator accounts.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4480?
CVE-2013-4480 is considered a critical vulnerability due to its ability to allow remote attackers to create administrator accounts.
How do I fix CVE-2013-4480?
To fix CVE-2013-4480, ensure that the web interface for creating the initial administrator user is disabled after the initial setup.
Which versions of Red Hat Satellite are affected by CVE-2013-4480?
CVE-2013-4480 affects Red Hat Satellite versions up to 5.6, including the versions with Embedded Oracle from 5.2 to 5.5.
Is there a workaround for CVE-2013-4480?
A workaround for CVE-2013-4480 involves restricting access to the web interface by limiting network access or using firewall rules.
Can CVE-2013-4480 be exploited remotely?
Yes, CVE-2013-4480 can be exploited remotely, allowing attackers to create unauthorized administrator accounts.