{"id":"CVE-2013-4436","aliases":[],"url":"https://o3.security/vulnerability/CVE-2013-4436","summary":"The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote attackers to have unspecified impact via a…","details":"The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote attackers to have unspecified impact via a man-in-the-middle (MITM) attack.","published":"2013-11-05T18:55:04.837","modified":"2026-06-16T23:57:13.637","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"FIX","url":"http://docs.saltstack.com/topics/releases/0.17.1.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2013/10/18/3"},{"type":"FIX","url":"http://docs.saltstack.com/topics/releases/0.17.1.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2013/10/18/3"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-16T23:57:13.637"}}