5.8
CVSSv2

CVE-2013-4962

Published: 20/08/2013 Updated: 10/07/2019
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

The reset password page in Puppet Enterprise prior to 3.0.1 does not force entry of the current password, which allows malicious users to modify user passwords by leveraging session hijacking, an unattended workstation, or other vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppet enterprise 2.5.1

puppet puppet enterprise

puppet puppet enterprise 2.8.3

puppet puppet enterprise 2.8.1

puppet puppet enterprise 2.5.2

puppet puppet enterprise 2.8.2

puppet puppet enterprise 2.8.0