VYPR
Medium severity5.6NVD Advisory· Published Jan 31, 2017· Updated May 13, 2026

CVE-2016-3176

CVE-2016-3176

Description

Salt before 2015.5.10 and 2015.8.x before 2015.8.8, when PAM external authentication is enabled, allows attackers to bypass the configured authentication service by passing an alternate service with a command sent to LocalClient.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
saltPyPI
< 2015.5.102015.5.10
saltPyPI
>= 2015.8, < 2015.8.82015.8.8

Affected products

8
  • Saltstack/Salt8 versions
    cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:a:saltstack:salt:*:*:*:*:*:*:*:*range: <=2015.5.9
    • cpe:2.3:a:saltstack:salt:2015.8.0:*:*:*:*:*:*:*
    • cpe:2.3:a:saltstack:salt:2015.8.1:*:*:*:*:*:*:*
    • cpe:2.3:a:saltstack:salt:2015.8.2:*:*:*:*:*:*:*
    • cpe:2.3:a:saltstack:salt:2015.8.3:*:*:*:*:*:*:*
    • cpe:2.3:a:saltstack:salt:2015.8.4:*:*:*:*:*:*:*
    • cpe:2.3:a:saltstack:salt:2015.8.5:*:*:*:*:*:*:*
    • cpe:2.3:a:saltstack:salt:2015.8.7:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.