CVE-2013-4436: SaltStack Salt
High severity, CVSS 9.3. EPSS: 1.8% chance of exploitation in the next 30 days.
The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote attackers to have unspecified impact via a man-in-the-middle (MITM) attack.
Affected products
- SaltStack Salt: version 0.17.0 only
Published 2013-11-05. Last modified 2026-06-16.