CVE-2024-38825 MEDIUM

CVE-2024-38825: CVE-2024-38825 Salt Advisory

Vendor Vmware
Product SALT
Published June 13, 2025
Last update June 13, 2025

CVSS base score

6.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

The salt.auth.pki module does not properly authenticate callers. The "password" field contains a public certificate which is validated against a CA certificate by the module. This is not pki authentication, as the caller does not need access to the corresponding private key for the authentication attempt to be accepted.

Key dates

02Disclosure timeline

June 13, 2025 CVE published
June 13, 2025 Record updated