CVE-2021-20256 PUBLISHED CVSS 5.300000190734863 MEDIUM

A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

EPSS 0.12% · 30.8th percentile

Risk Scores

CVSS v3.1
5.300000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS Score
0.12%
30.8th percentile

Affected Products

VendorProductVersions
n/aRed Hat SatelliteAs shipped in Red Hat Satellite 6
redhatsatellite6.0

Timeline

References

Open in Interactive Console →