Authentication Flaw in Salt Project's PKI Module Affects Multiple Versions
CVE-2024-38825

6.4MEDIUM

Key Information:

Vendor

Vmware

Status
Vendor
CVE Published:
13 June 2025

What is CVE-2024-38825?

The salt.auth.pki module contains an authentication flaw that allows unauthorized access. In this module, the 'password' field is expected to contain a public certificate, which is incorrectly validated against a Certificate Authority (CA) certificate. Consequently, the authentication process does not require the caller to possess the corresponding private key, thereby circumventing proper PKI authentication measures. This vulnerability could potentially allow malicious actors to bypass security protocols and execute unauthorized actions within the affected systems.

Affected Version(s)

SALT 3006.x < 3006.12

SALT 3007.x < 3007.4

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-38825 : Authentication Flaw in Salt Project's PKI Module Affects Multiple Versions