CVE-2015-4100

Published: Dic 21, 2017 Last Modified: Apr 20, 2025 EU-VD ID: EUVD-2015-4125 Aliases: GSD-2015-4100
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,8
Attack Vector: network
Attack Complexity: high
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: none
Availability: high
MEDIUM 4,9
Access Vector: network
Access Complexity: medium
Authentication: single
Confidentiality: partial
Integrity: none
Availability: partial

Description

AI Translation Available

Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificate trusted by the master, aka a 'Certificate Authority Reverse Proxy Vulnerability.'

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0027
Percentile
0,5th
Updated

EPSS Score Trend (Last 90 Days)

295

Improper Certificate Validation

Draft
Common Consequences
Security Scopes Affected:
Integrity Authentication
Potential Impacts:
Bypass Protection Mechanism Gain Privileges Or Assume Identity
Applicable Platforms
Technologies: Mobile, Not Technology-Specific, Web Based
View CWE Details
Application

Puppet Enterprise by Puppet

cpe:2.3:a:puppet:puppet_enterprise:3.8.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Puppet Enterprise by Puppet

Version Range Affected
From 3.7.0 (inclusive)
To 3.7.2 (inclusive)
cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://puppet.com/security/cve/CVE-2015-4100
https://puppet.com/security/cve/CVE-2015-4100