← Zuruck zu CVEs
CVE-2016-2786
CRITICAL9.8
Beschreibung
The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certificates, which might allow remote attackers to spoof brokers and execute arbitrary commands via a crafted certificate.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht6/10/2016
Zuletzt geandert4/12/2025
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
puppet:puppet_agentpuppet:puppet_enterprise
Schwachen (CWE)
CWE-20
Referenzen
https://puppet.com/security/cve/CVE-2016-2786(cve@mitre.org)
https://security.gentoo.org/glsa/201606-02(cve@mitre.org)
https://puppet.com/security/cve/CVE-2016-2786(af854a3a-2127-422b-91ae-364da2661108)
https://security.gentoo.org/glsa/201606-02(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.