5
CVE-2013-1654
- EPSS 0.51%
- Published 20.03.2013 16:55:01
- Last modified 11.04.2025 00:51:21
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol between client and master, which allows remote attackers to conduct SSLv2 downgrade attacks against SSLv3 sessions via unspecified vectors.
Data is provided by the National Vulnerability Database (NVD)
Puppetlabs ≫ Puppet Version2.7.0
Puppetlabs ≫ Puppet Version2.7.1
Puppetlabs ≫ Puppet Version2.7.19
Puppetlabs ≫ Puppet Version2.7.20
Puppetlabs ≫ Puppet Version2.7.20 Updaterc1
Puppet ≫ Puppet Enterprise Version3.1.0
Puppetlabs ≫ Puppet Version2.7.0 Update- Editionenterprise
Puppetlabs ≫ Puppet Version2.7.1 Update- Editionenterprise
Canonical ≫ Ubuntu Linux Version11.10
Canonical ≫ Ubuntu Linux Version12.04 Update- Editionlts
Canonical ≫ Ubuntu Linux Version12.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.51% | 0.655 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|