Vulnerability Name: | CVE-2013-2056 (CCN-84425) | ||||||||
Assigned: | 2013-05-21 | ||||||||
Published: | 2013-05-21 | ||||||||
Updated: | 2022-02-03 | ||||||||
Summary: | The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5.3, 5.4, and 5.5 does not properly check client "authenticity," which allows remote attackers to obtain channel content by skipping the initial authentication call. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-287 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-2056 Source: REDHAT Type: Vendor Advisory RHSA-2013:0848 Source: SECUNIA Type: Vendor Advisory 53487 Source: OSVDB Type: UNKNOWN 93566 Source: CCN Type: BID-60075 Red Hat Network Satellite CVE-2013-2056 Authentication Bypass Vulnerability Source: CCN Type: Red Hat Bugzilla Bug 959524 CVE-2013-2056 Satellite: Inter-Satellite Sync (ISS) does not require authentication/authorization Source: XF Type: UNKNOWN network-cve20132056-sec-bypass(84425) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |