Impact
An unauthenticated attacker can retrieve the RPC secret in plaintext by querying the vendor data metadata endpoint in Canonical MAAS when the machine is deployed with the "register as rack" option enabled and the system ID is known or can be inferred. The exposed secret can be used to access or impersonate MAAS services, potentially allowing the attacker to manage or control the infrastructure. This is an information disclosure vulnerability that compromises confidentiality, providing attackers with credentials that enable further exploitation.
Affected Systems
Canonical MAAS on Linux versions earlier than 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 are affected by this disclosure. All other MAAS releases are not vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS data is not available, but the vulnerability does not appear in CISA’s KEV catalog and is considered to have a limited exploitation window. The likely attack vector is a simple, unauthenticated network request to the metadata endpoint once the attacker obtains or guesses the system ID, with no additional credentials required.
OpenCVE Enrichment