CVE-2016-2788

EUVD-2016-3861
MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the mco ping command.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
Affected Products (NVD)
VendorProductVersion
puppetmarionette_collective
2.7.0
puppetmarionette_collective
2.8.0
puppetmarionette_collective
2.8.1
puppetmarionette_collective
2.8.2
puppetmarionette_collective
2.8.3
puppetmarionette_collective
2.8.4
puppetmarionette_collective
2.8.5
puppetmarionette_collective
2.8.6
puppetmarionette_collective
2.8.7
puppetmarionette_collective
2.8.8
puppetpuppet_enterprise
3.8.0 ≤
𝑥
< 3.8.6
puppetpuppet_enterprise
2016.2.0 ≤
𝑥
< 2016.2.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
mcollective
bookworm
2.12.5+dfsg-1.1
fixed
bullseye
2.12.5+dfsg-1
fixed
jessie
no-dsa
wheezy
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mcollective
artful
ignored
bionic
not-affected
cosmic
not-affected
precise
ignored
trusty
dne
xenial
not-affected
yakkety
ignored
zesty
ignored