Skip to Main Content

Bruin Learn is temporarily unavailable; we’re aware of the issue and working to resolve it as quickly as possible.

SaltStack FrameWork Vulnerabilities Affecting Cisco Products

On April 29, 2020, the Salt Open Core team notified their community regarding the following two CVE-IDs:

  • CVE-2020-11651: Authentication Bypass Vulnerability
  • CVE-2020-11652: Directory Traversal Vulnerability

Cisco Modeling Labs Corporate Edition (CML) and Cisco Virtual Internet Routing Lab Personal Edition (VIRL-PE) incorporate a version of SaltStack that is running the salt-master service that is affected by these vulnerabilities.

Cisco has released software updates that address these vulnerabilities. There is a workaround that addresses these vulnerabilities.

This advisory is available at the following link: Cisco Security Advisory