Salt Master authentication protocol downgrade may enable minion impersonation
Vulnerability Description
Salt contains an authentication protocol version downgrade weakness that can allow a malicious minion to bypass newer authentication/security features by using an older request payload format, enabling minion impersonation and circumventing protections introduced in response to prior issues.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-62349
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Barney Sowood
References
Affected Vendor
Salt Project
View all reports →