Incorrect Implementation of Authentication Algorithm in SUSE Linux Enterprise Server - CVE-2021-25315

 

Incorrect Implementation of Authentication Algorithm in SUSE Linux Enterprise Server - CVE-2021-25315

Published: March 22, 2021


Vulnerability identifier: #VU51588
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-25315
CWE-ID: CWE-303
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

the vulnerability exists due to incorrect implementation of authentication algorithm in SUSE implementation of salt before 3002.2-3. A local user can execute arbitrary code via salt without providing valid credentials.


Affected software

SUSE Linux Enterprise Server
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE MicroOS
SUSE Enterprise Storage
SUSE Manager Debian
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Transactional Server
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Module for Basesystem
SUSE Manager Ubuntu
SUSE Manager
python2-distro
python3-distro
spacecmd
salt-minion
salt-common
salt
salt-zsh-completion
python3-salt
salt-transactional-update
salt-bash-completion
salt-fish-completion
salt-syndic
salt-standalone-formulas-configuration
salt-ssh
salt-proxy
salt-master
salt-doc
salt-cloud
salt-api
Dell EMC VxRail Appliance

How to mitigate CVE-2021-25315

Install updates from vendor's website.

python2-distro - update to 1.5.0-3.5.1
python3-distro - update to 1.5.0-3.5.1
spacecmd - addressed in versions 4.2.8-2.9.1, 4.2.8-2.24.3, 4.2.8-26.2
Dell EMC VxRail Appliance - update to 7.0.203
salt-minion - addressed in versions 3002.2+ds-1+2.14.1, 3002.2+ds-1+2.19.1, 3002.2+ds-1+27.34.1, 3002.2-8.41.8.1, 3002.2-37.1
salt-common - addressed in versions 3002.2+ds-1+2.14.1, 3002.2+ds-1+2.19.1, 3002.2+ds-1+27.34.1
salt - addressed in versions 3002.2-8.41.8.1, 3002.2-37.1
salt-zsh-completion - addressed in versions 3002.2-8.41.8.1, 3002.2-37.1
python3-salt - addressed in versions 3002.2-8.41.8.1, 3002.2-37.1
salt-transactional-update - addressed in versions 3002.2-8.41.8.1, 3002.2-37.1
salt-bash-completion - addressed in versions 3002.2-8.41.8.1, 3002.2-37.1
salt-fish-completion - addressed in versions 3002.2-8.41.8.1, 3002.2-37.1
salt-syndic - addressed in versions 3002.2-8.41.8.1, 3002.2-37.1
salt-standalone-formulas-configuration - addressed in versions 3002.2-8.41.8.1, 3002.2-37.1
salt-ssh - addressed in versions 3002.2-8.41.8.1, 3002.2-37.1
salt-proxy - addressed in versions 3002.2-8.41.8.1, 3002.2-37.1
salt-master - addressed in versions 3002.2-8.41.8.1, 3002.2-37.1
salt-doc - addressed in versions 3002.2-8.41.8.1, 3002.2-37.1
salt-cloud - addressed in versions 3002.2-8.41.8.1, 3002.2-37.1
salt-api - addressed in versions 3002.2-8.41.8.1, 3002.2-37.1

External References

Related Security Bulletins