PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-3176 Saltstack CVE debrief

CVE-2016-3176 is a Salt authentication flaw affecting deployments that use PAM external authentication. In the affected versions, an attacker could bypass the configured authentication service by sending an alternate service value with a command to LocalClient. The issue is rated Medium by NVD and is addressed by the Salt release updates referenced in the vendor notes.

Vendor
Saltstack
Product
Salt
CVSS
MEDIUM 5.6
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-31
Original CVE updated
2026-05-13
Advisory published
2017-01-31
Advisory updated
2026-05-13

Who should care

Salt administrators and operators running PAM external authentication, especially on versions earlier than 2015.5.10 or 2015.8.8. Security teams should pay particular attention where LocalClient access is exposed to untrusted users or automation paths.

Technical summary

According to the NVD description, Salt before 2015.5.10 and 2015.8.x before 2015.8.8 allows an authentication bypass when PAM external authentication is enabled. The weakness is classified as CWE-287 (Improper Authentication). NVD’s CVSS vector is CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L, indicating network reachability but with some conditions needed for successful abuse.

Defensive priority

Medium. The flaw affects authentication trust boundaries, so it should be treated as important in environments that expose Salt authentication workflows, even though the CVSS score is not critical.

Recommended defensive actions

  • Upgrade Salt to 2015.5.10 or later, or 2015.8.8 or later, using the vendor release notes referenced by NVD.
  • Confirm whether PAM external authentication is enabled anywhere in your Salt environment; prioritize affected systems first.
  • Review who can submit commands to LocalClient and restrict access to trusted administrators and automation only.
  • Audit authentication-related logs for unexpected service values or anomalous LocalClient command usage.
  • If upgrading is delayed, reduce exposure by tightening access controls around Salt services and administrative interfaces.

Evidence notes

This debrief is based only on the supplied NVD record, its published/modified dates, the NVD CVSS vector and CWE mapping, and the official Salt release-note links referenced by the record. The vendor reference URLs in the corpus are the only remediation sources used here. No exploit code, reproduction steps, or unsupported version claims were added beyond the provided affected-version ranges.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-3176 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-3176

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-3176 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-3176

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.