VDB
CVE-2016-9599
CVE-2016-9599
PUBLISHED
CVSS 7.099999904632568 HIGH
puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of TCP/UDP rules with empty port values. If SSL is enabled, a malicious user could use these open ports to gain access to unauthorized resources.
EPSS 0.83% · 54.5th percentile
Risk Scores
CVSS 3.0
7.099999904632568
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
EPSS Score
0.83%
54.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| unspecified | puppet-tripleo | puppet-tripleo 5.5.0, * |
| openstack | puppet-tripleo | 5.5.0, 6.2.0 |
| redhat | openstack | 10 |
Timeline
- Apr 23, 2018 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 18, 2023 EPSS Score