First published: Fri Feb 19 2021(Updated: )
A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Satellite | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20256 is a vulnerability found in Red Hat Satellite where the BMC interface exposes the password through the API to an authenticated local attacker with view_hosts permission.
The severity of CVE-2021-20256 is medium with a CVSS score of 5.3.
CVE-2021-20256 may lead to data confidentiality and integrity issues as well as system availability.
Red Hat Satellite version 6.0 is affected by CVE-2021-20256.
To fix CVE-2021-20256, it is recommended to apply the relevant security patches provided by Red Hat.