CVE-2013-4966Improper Authentication in Enterprise

Severity
6.4MEDIUMNVD
EPSS
0.2%
top 54.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 9
Latest updateMay 14

Description

The master external node classification script in Puppet Enterprise before 3.2.0 does not verify the identity of consoles, which allows remote attackers to create arbitrary classifications on the master by spoofing a console.

CVSS vector

AV:N/AC:L/C:P/I:P/A:NExploitability: 10.0 | Impact: 4.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-r6x2-cpwm-cr43: The master external node classification script in Puppet Enterprise before 32022-05-14
CVEList
CVE-2013-4966: The master external node classification script in Puppet Enterprise before 32014-03-07

📋Vendor Advisories

1
Debian
CVE-2013-4966: puppet - The master external node classification script in Puppet Enterprise before 3.2.0...2013

💬Community

1
Bugzilla
CVE-2011-4966 freeradius: does not respect expired passwords when using the unix module2012-11-21
CVE-2013-4966 — Improper Authentication in Enterprise | cvebase