CVE-2024-4871 is a medium-severity vulnerability in Satellite that allows for man-in-the-middle attacks during remote execution jobs. The flaw stems from Satellite's use of "-o StrictHostKeyChecking=no," which bypasses SSH key verification, enabling an attacker to forge an SSH key. This can lead to denial of service, secret leakage, or other issues, though it does not directly permit unauthorized remote execution on the Satellite itself. With a CVSS score of 6.8, this vulnerability has a high impact on confidentiality and integrity, but requires high attack complexity and low privileges. Currently, there is no known active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat Satellite 6.15 For RHEL 8 | Range not provided by sourceCNA affecteddefault affected | |
| Https://Github.Com/Theforeman/Foreman | Foreman | 3.9.1.8CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.