6.4
CVSSv2

CVE-2013-4966

Published: 09/03/2014 Updated: 10/07/2019
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

The master external node classification script in Puppet Enterprise prior to 3.2.0 does not verify the identity of consoles, which allows remote malicious users to create arbitrary classifications on the master by spoofing a console.

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppet enterprise 3.1.0

puppet puppet enterprise

puppet puppet enterprise 3.0.0

puppet puppet enterprise 3.0.1