CVE-2016-5716
published 2017-08-09CVE-2016-5716: The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code execution on the…
PriorityP349high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
1.59%
73.6th percentile
The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code execution on the console node.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
| puppet | puppet_enterprise | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_debian8.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2016-5716: puppet - The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes un...
vendor_debian·2016·CVSS 8.8
CVE-2016-5716 [HIGH] CVE-2016-5716: puppet - The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes un...
The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code execution on the console node.
Scope: local
bullseye: resolved
GHSA
GHSA-3mf2-j3p3-w43q: The console in Puppet Enterprise 2015
ghsa_unreviewed·2022-05-14
CVE-2016-5716 [HIGH] CWE-134 GHSA-3mf2-j3p3-w43q: The console in Puppet Enterprise 2015
The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code execution on the console node.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-08-09
Published