CVE-2016-5714
Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to bypass a host whitelist protection mechanism and execute arbitrary code on Puppet nodes via vectors related to command validation, aka…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.24%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to bypass a host whitelist protection mechanism and execute arbitrary code on Puppet nodes via vectors related to command validation, aka "Puppet Execution Protocol (PXP) Command Whitelist Validation Vulnerability."
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.24% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- puppet/puppet enterprise · puppet/puppet agent
- Source
- cve@mitre.org
References
- https://bugs.gentoo.org/597684Issue Tracking, Third Party Advisory
- https://puppet.com/security/cve/cve-2016-5714Vendor Advisory
- https://puppet.com/security/cve/pxp-agent-oct-2016Issue Tracking, Vendor Advisory
- https://security.gentoo.org/glsa/201710-12Third Party Advisory
- https://bugs.gentoo.org/597684Issue Tracking, Third Party Advisory
- https://puppet.com/security/cve/cve-2016-5714Vendor Advisory
- https://puppet.com/security/cve/pxp-agent-oct-2016Issue Tracking, Vendor Advisory
- https://security.gentoo.org/glsa/201710-12Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.