CVE-2014-3251 — Race Condition in Enterprise
Severity
4.4MEDIUMNVD
EPSS
0.0%
top 92.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 12
Latest updateMay 14
Description
The MCollective aes_security plugin, as used in Puppet Enterprise before 3.3.0 and Mcollective before 2.5.3, does not properly validate new server certificates based on the CA certificate, which allows local users to establish unauthorized Mcollective connections via unspecified vectors related to a race condition.
CVSS vector
AV:L/AC:M/C:P/I:P/A:PExploitability: 3.4 | Impact: 6.4
Affected Packages2 packages
🔴Vulnerability Details
3GHSA▶
GHSA-q495-m6p3-c645: The MCollective aes_security plugin, as used in Puppet Enterprise before 3↗2022-05-14
CVEList▶
CVE-2014-3251: The MCollective aes_security plugin, as used in Puppet Enterprise before 3↗2014-08-12
OSV▶
CVE-2014-3251: The MCollective aes_security plugin, as used in Puppet Enterprise before 3↗2014-08-12
📋Vendor Advisories
2💬Community
5Bugzilla
▶