cbcvebase.
CVE-2016-5716
published 2017-08-09

CVE-2016-5716: The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code execution on the…

PriorityP349high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
1.59%
73.6th percentile
The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code execution on the console node.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianpuppet
puppetpuppet_enterprise
puppetpuppet_enterprise
puppetpuppet_enterprise
puppetpuppet_enterprise
puppetpuppet_enterprise
puppetpuppet_enterprise
puppetpuppet_enterprise
puppetpuppet_enterprise
puppetpuppet_enterprise
puppetpuppet_enterprise
puppetpuppet_enterprise
puppetpuppet_enterprise
puppetpuppet_enterprise

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_debian8.8LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.