8.8
CVSSv3

CVE-2016-5716

Published: 09/08/2017 Updated: 10/07/2019
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The console in Puppet Enterprise 2015.x and 2016.x before 2016.4.0 includes unsafe string reads that potentially allows for remote code execution on the console node.

Vulnerable Product Search on Vulmon Subscribe to Product

puppet puppet enterprise 2015.3.2

puppet puppet enterprise 2015.2.3

puppet puppet enterprise 2015.2.0

puppet puppet enterprise 2015.3.3

puppet puppet enterprise 2016.2.1

puppet puppet enterprise 2016.2.0

puppet puppet enterprise 2016.1.1

puppet puppet enterprise 2015.3.1

puppet puppet enterprise 2015.2.1

puppet puppet enterprise 2016.1.2

puppet puppet enterprise 2015.3.0

puppet puppet enterprise 2015.2.2