CVE-2016-2786

Description

The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certificates, which might allow remote attackers to spoof brokers and execute arbitrary commands via a crafted certificate.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.71

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2016-2786 are affected in Puppet Agent (x64) 1.3.0Windows
Vulnerabilities CVE-2016-2786 are affected in Puppet Agent (x64) 1.3.1Windows
Vulnerabilities CVE-2016-2786 are affected in Puppet Agent (x64) 1.3.2Windows
Vulnerabilities CVE-2016-2786 are affected in Puppet Agent (x64) 1.3.4Windows
Vulnerabilities CVE-2016-2786 are affected in Puppet Agent (x64) 1.3.5Windows
Vulnerabilities CVE-2016-2786 are affected in Puppet Agent 1.3.0Windows
Vulnerabilities CVE-2016-2786 are affected in Puppet Agent 1.3.1Windows
Vulnerabilities CVE-2016-2786 are affected in Puppet Agent 1.3.2Windows
Vulnerabilities CVE-2016-2786 are affected in Puppet Agent 1.3.4Windows
Vulnerabilities CVE-2016-2786 are affected in Puppet Agent 1.3.5Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-342464Puppet Agent (x64) (8.10.0)
PATCH-342464Puppet Agent (x64) (8.10.0)
PATCH-342464Puppet Agent (x64) (8.10.0)
PATCH-342464Puppet Agent (x64) (8.10.0)
PATCH-342464Puppet Agent (x64) (8.10.0)
PATCH-342463Puppet Agent (8.10.0)
PATCH-342463Puppet Agent (8.10.0)
PATCH-342463Puppet Agent (8.10.0)
PATCH-342463Puppet Agent (8.10.0)
PATCH-342463Puppet Agent (8.10.0)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234