TROYANOSYVIRUS
Back to CVEs

CVE-2016-5714

HIGH
7.2

Description

Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to bypass a host whitelist protection mechanism and execute arbitrary code on Puppet nodes via vectors related to command validation, aka "Puppet Execution Protocol (PXP) Command Whitelist Validation Vulnerability."

CVE Details

CVSS v3.1 Score7.2
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredHIGH
User InteractionNONE
Published10/18/2017
Last Modified4/20/2025
Sourcenvd
Honeypot Sightings0

Affected Products

puppet:puppet_agentpuppet:puppet_enterprise

Weaknesses (CWE)

CWE-284

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.