Vulnerability Name: | CVE-2012-3408 (CCN-77287) | ||||||||
Assigned: | 2012-07-31 | ||||||||
Published: | 2012-07-31 | ||||||||
Updated: | 2022-01-24 | ||||||||
Summary: | lib/puppet/network/authstore.rb in Puppet before 2.7.18, and Puppet Enterprise before 2.5.2, supports use of IP addresses in certnames without warning of potential risks, which might allow remote attackers to spoof an agent by acquiring a previously used IP address. | ||||||||
CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N) 1.9 Low (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-287 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2012-3408 Source: CCN Type: Puppet Labs Web site CVE-2012-3408 (Agent Impersonation) Source: CONFIRM Type: Vendor Advisory http://puppetlabs.com/security/cve/cve-2012-3408/ Source: CCN Type: OSVDB ID: 84866 Puppet lib/puppet/network/authstore.rb Certname IP Address Remote Agent Spoofing Weakness Source: CCN Type: BID-54737 Puppet Certificate IP Address Host Impersonation Security Bypass Vulnerability Source: CONFIRM Type: Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=839166 Source: XF Type: UNKNOWN puppet-certificate-spoofing(77287) Source: CONFIRM Type: Exploit, Patch, Third Party Advisory https://github.com/puppetlabs/puppet/commit/ab9150baa1b738467a33b01df1d90e076253fbbd | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |