Vulnerability identifier: #VU38511
Vulnerability risk: High
CVSSv4.0: 6.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2016-5716
CWE-ID:
CWE-134
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Puppet Enterprise
Client/Desktop applications /
Software for system administration
Vendor: Puppet Labs
Description
The vulnerability allows a remote authenticated user to execute arbitrary code.
The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code execution on the console node.
Mitigation
Install update from vendor's website.
Vulnerable software versions
Puppet Enterprise: 2015.2.0 - 2016.2.1
External links
https://puppet.com/security/cve/pe-console-oct-2016
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.