VDB

CVE-2016-9599

CVE-2016-9599 PUBLISHED CVSS 7.099999904632568 HIGH

puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of TCP/UDP rules with empty port values. If SSL is enabled, a malicious user could use these open ports to gain access to unauthorized resources.

EPSS 0.83% · 54.5th percentile

Risk Scores

CVSS 3.0
7.099999904632568
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
EPSS Score
0.83%
54.5th percentile

Affected Products

VendorProductVersions
unspecifiedpuppet-tripleopuppet-tripleo 5.5.0, *
openstackpuppet-tripleo5.5.0, 6.2.0
redhatopenstack10

Timeline

  • Apr 23, 2018 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 21, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 27, 2022 EPSS Score
  • Dec 19, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • May 26, 2023 EPSS Score
  • Jul 18, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›