Vulnerability record · CVE-2021-3197 · published 27 February 2021
CVE-2021-3197: SaltStack salt-api SSH client shell injection via ProxyCommand
Saltstack · Salt
SaltStack Salt before 3002.5 contains a shell injection flaw in the salt-api SSH client. An attacker can inject commands by including a ProxyCommand in an argument or by supplying crafted ssh_options in an API request. Because salt-api is a remote management interface, successful exploitation can compromise the Salt master and any systems it controls.
Description
An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no privileges or interaction required, and very high EPSS make this a top remediation priority despite no KEV listing.
What it is
SaltStack Salt before 3002.5 contains a shell injection flaw in the salt-api SSH client. An attacker can inject commands by including a ProxyCommand in an argument or by supplying crafted ssh_options in an API request. Because salt-api is a remote management interface, successful exploitation can compromise the Salt master and any systems it controls.
Impact
An attacker gains arbitrary command execution in the context of the salt-api process, which typically runs with high privileges on the Salt master. From there they can pivot to managed minions and other infrastructure.
Attack surface
The flaw is reachable over the network through the salt-api SSH client endpoint, as reflected by the CVSS vector AV:N/PR:N/UI:N. No authentication or user interaction is required per that vector, though the record does not detail the exact API call path.
Exploitation
CVE-2021-3197 is not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.723 probability (99.4th percentile), indicating elevated likelihood of attempted exploitation. References are advisories and release notes only, with no public exploit tag.
What to do
- Upgrade SaltStack Salt to 3002.5 or later, or apply the vendor patch referenced in the SaltStack security announcement.
- Update Salt packages on Debian, Fedora and Gentoo hosts using the respective distribution advisories.
- Restrict network access to salt-api to trusted management networks and disable it where not required.
- Run salt-api with least privilege and avoid exposing it directly to untrusted networks.
- Audit salt-api requests and ssh_options handling for unexpected ProxyCommand values.
Detection
- Monitor salt-api logs for requests containing ProxyCommand or unusual ssh_options values.
- Alert on child processes spawned by salt-api that invoke ssh or shell interpreters with unexpected arguments.
- Review network flows to salt-api ports from untrusted sources and flag anomalous clients.
- Search host telemetry for command lines containing ProxyCommand originating from the Salt master process tree.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-3197 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-3197), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.