CVE-2016-2788
9.8
CRITICAL
CVSS 3.1
EPSS 2.0%
Description
MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the mco ping command.
How to fix CVE-2016-2788
To remediate CVE-2016-2788, upgrade the affected package to a fixed version below.
- Debian/mcollective—upgrade to 2.12.0+dfsg-1 or later
Is CVE-2016-2788 being exploited?
Low — EPSS is 2.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.12.0+dfsg-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |