Vulnerability CVE-2016-9686


Published: 2017-02-08   Modified: 2017-02-09

Description:
The Puppet Communications Protocol (PCP) Broker incorrectly validates message header sizes. An attacker could use this to crash the PCP Broker, preventing commands from being sent to agents. This is resolved in Puppet Enterprise 2016.4.3 and 2016.5.2.

Type:

CWE-20

(Improper Input Validation)

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Puppetlabs -> Puppet enterprise 
Puppet -> Puppet enterprise 

 References:
https://puppet.com/security/cve/cve-2016-9686

Copyright 2024, cxsecurity.com

 

Back to Top