5
CVE-2013-1654
- EPSS 2.95%
- Veröffentlicht 20.03.2013 16:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol between client and master, which allows remote attackers to conduct SSLv2 downgrade attacks against SSLv3 sessions via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Puppetlabs ≫ Puppet Version 2.7.0
Puppetlabs ≫ Puppet Version 2.7.1
Puppetlabs ≫ Puppet Version 2.7.19
Puppetlabs ≫ Puppet Version 2.7.20
Puppetlabs ≫ Puppet Version 2.7.20 Update rc1
Puppet ≫ Puppet Enterprise Version 3.1.0
Puppetlabs ≫ Puppet Version 2.7.0 Update - Edition enterprise
Puppetlabs ≫ Puppet Version 2.7.1 Update - Edition enterprise
Canonical ≫ Ubuntu Linux Version 11.10
Canonical ≫ Ubuntu Linux Version 12.04 Update - Edition lts
Canonical ≫ Ubuntu Linux Version 12.10
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.95% | 0.854 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
http://www.securityfocus.com/bid/64758
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00004.html
http://lists.opensuse.org/opensuse-updates/2013-04/msg00056.html
http://rhn.redhat.com/errata/RHSA-2013-0710.html
http://secunia.com/advisories/52596
http://ubuntu.com/usn/usn-1759-1
http://www.debian.org/security/2013/dsa-2643
https://puppetlabs.com/security/cve/cve-2013-1654/