CVE-2016-5714

7.2 HIGH
Published: October 18, 2017 Modified: May 13, 2026
View on NVD

Description

Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to bypass a host whitelist protection mechanism and execute arbitrary code on Puppet nodes via vectors related to command validation, aka "Puppet Execution Protocol (PXP) Command Whitelist Validation Vulnerability."

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://bugs.gentoo.org/597684
Source: cve@mitre.org
Issue Tracking Third Party Advisory
https://puppet.com/security/cve/cve-2016-5714
Source: cve@mitre.org
Vendor Advisory
https://puppet.com/security/cve/pxp-agent-oct-2016
Source: cve@mitre.org
Issue Tracking Vendor Advisory
https://security.gentoo.org/glsa/201710-12
Source: cve@mitre.org
Third Party Advisory
https://bugs.gentoo.org/597684
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Third Party Advisory
https://puppet.com/security/cve/cve-2016-5714
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
https://puppet.com/security/cve/pxp-agent-oct-2016
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Vendor Advisory
https://security.gentoo.org/glsa/201710-12
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

8 reference(s) from NVD

Quick Stats

CVSS v3 Score
7.2 / 10.0
EPSS (Exploit Probability)
2.2%
81th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

puppet