CVE-2016-2788

MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the mco ping command.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
VendorProductVersion
puppetmarionette_collective
2.7.0
puppetmarionette_collective
2.8.0
puppetmarionette_collective
2.8.1
puppetmarionette_collective
2.8.2
puppetmarionette_collective
2.8.3
puppetmarionette_collective
2.8.4
puppetmarionette_collective
2.8.5
puppetmarionette_collective
2.8.6
puppetmarionette_collective
2.8.7
puppetmarionette_collective
2.8.8
puppetpuppet_enterprise
3.8.0 ≤
𝑥
< 3.8.6
puppetpuppet_enterprise
2016.2.0 ≤
𝑥
< 2016.2.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
mcollective
bullseye
2.12.5+dfsg-1
fixed
jessie
no-dsa
wheezy
no-dsa
bookworm
2.12.5+dfsg-1.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mcollective
cosmic
not-affected
bionic
not-affected
artful
ignored
zesty
ignored
yakkety
ignored
xenial
not-affected
trusty
dne
precise
ignored