Improper Authentication in etcd - #VU130093

 

Improper Authentication in etcd - #VU130093

Published: August 5, 2020 / Updated: May 5, 2026


Vulnerability identifier: #VU130093
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass endpoint authentication.

The vulnerability exists due to improper authentication in gateway endpoint authentication when handling endpoints discovered from DNS SRV records after their authentication settings change. A remote user can cause the gateway to continue trusting an endpoint that is no longer authenticated to bypass endpoint authentication.

The gateway authenticates detected endpoints only once.


Affected software

etcd

Remediation

Install security update from vendor's website.

etcd - addressed in versions 3.3.23, 3.4.10

External References

Related Security Bulletins