๐Ÿ” CVE Alert

CVE-2023-4320

HIGH 7.6

Satellite: arithmetic overflow in satellite

CVSS Score
7.6
EPSS Score
0.0%
EPSS Percentile
0th

An arithmetic overflow flaw was found in Satellite when creating a new personal access token. This flaw allows an attacker who uses this arithmetic overflow to create personal access tokens that are valid indefinitely, resulting in damage to the system's integrity.

CWE CWE-613
Vendor red hat
Product red hat satellite 6.15 for rhel 8
Published Dec 18, 2023
Last Updated Nov 20, 2025
Stay Ahead of the Next One

Get instant alerts for red hat red hat satellite 6.15 for rhel 8

Be the first to know when new high vulnerabilities affecting red hat red hat satellite 6.15 for rhel 8 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
Low

Affected Versions

Red Hat / Red Hat Satellite 6.15 for RHEL 8
All versions affected
Red Hat / Red Hat Satellite 6.15 for RHEL 8
All versions affected
Red Hat / Red Hat Satellite 6.15 for RHEL 8
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/errata/RHSA-2024:2010 access.redhat.com: https://access.redhat.com/security/cve/CVE-2023-4320 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2231814