Vulnerability Name: | CVE-2013-4966 (CCN-91736) | ||||||||
Assigned: | 2013-07-29 | ||||||||
Published: | 2014-03-04 | ||||||||
Updated: | 2019-07-10 | ||||||||
Summary: | The master external node classification script in Puppet Enterprise before 3.2.0 does not verify the identity of consoles, which allows remote attackers to create arbitrary classifications on the master by spoofing a console. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N) 4.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-287 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-4966 Source: CCN Type: Puppet Labs Web Site CVE-2013-4966 (Master external node classification script vulnerable to console impersonation) Source: CONFIRM Type: Vendor Advisory http://puppetlabs.com/security/cve/cve-2013-4966 Source: CCN Type: SA57159 Puppet Enterprise Multiple Vulnerabilities Source: CCN Type: BID-65992 Puppet Enterprise Console Impersonation Security Bypass Vulnerability Source: SECTRACK Type: UNKNOWN 1029873 Source: XF Type: UNKNOWN puppet-cve20134966-spoofing(91736) Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-4966 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |