Network Satellite
Vendor:
First CVE: May 23, 2008 · Active for 18 years
10
Total CVEs
More Total CVEs than 88% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Network Satellite over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 23, 2008
18 years ago
Most Recent CVE
May 14, 2015
4,092 days ago
CVE Severity & Scoring
Network Satellite10 CVEs
10%
70%
20%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network4 (40.0%)
Unknown6 (60.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (40.0%)
High0 (0.0%)
Unknown6 (60.0%)
User Interaction
None0 (0.0%)
Unknown6 (60.0%)
Required4 (40.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None3 (30.0%)
Unknown6 (60.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-2143MEDIUM The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to ga | Apr 17, 2014 | 6.5 | 63 | NO | YES |
CVE-2011-1594MEDIUM A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to arbitrary web sites by manipulati | Feb 5, 2014 | 6.5 | 21 | NO | NO |
CVE-2014-8162HIGH XML external entity (XXE) in the RPC interface in Spacewalk and Red Hat Network (RHN) Satellite 5.7 and earlier allows remote attackers to read arbitrary files and possibly have ot | May 14, 2015 | 7.5 | 20 | NO | NO |
CVE-2013-4480HIGH Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which allows remote attackers to create administrator ac | Nov 18, 2013 | 7.5 | 20 | NO | NO |
CVE-2011-3344MEDIUM A flaw was found in Spacewalk. A remote attacker can exploit a cross-site scripting (XSS) vulnerability in the Lookup Login/Password form by injecting arbitrary web script or HTML | Feb 5, 2014 | 5.4 | 19 | NO | NO |
CVE-2011-2927MEDIUM A flaw was found in Spacewalk and Red Hat Network Satellite. This vulnerability, known as cross-site scripting (XSS), allows remote attackers to inject malicious web scripts or HTM | Feb 5, 2014 | 5.4 | 19 | NO | NO |
CVE-2011-2920MEDIUM A flaw was found in Spacewalk and Red Hat Network Satellite. This cross-site scripting (XSS) vulnerability allows a remote attacker to inject arbitrary web script or HTML into web | Feb 5, 2014 | 5.5 | 19 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite before 5.7.0 allow remote authenticated users to inject arbitrary web script or | Jan 15, 2015 | 3.5 | 16 | NO | NO |
CVE-2011-2919MEDIUM Cross-site scripting (XSS) vulnerability in Spacewalk 1.6, as used in Red Hat Network (RHN) Satellite, allows remote attackers to inject arbitrary web script or HTML via the QueryS | Feb 5, 2014 | 4.3 | 16 | NO | NO |
CVE-2007-5961MEDIUM Cross-site scripting (XSS) vulnerability in the Red Hat Network channel search feature, as used in RHN and Red Hat Network Satellite before 5.0.2, allows remote attackers to inject | May 23, 2008 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
10.0% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Network Satellite
Top CWEs
Versions
No cataloged versions.