CVE-2016-5713
Estado: ModificadaCrítica (9.8)—
Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet runs. This could allow unauthorized code to be loaded. This bug was first introduced in Puppet Agent 1.3.0.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.02%
- Percentil entre todas las CVEs puntuadas: 80
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-94
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2016-5713",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@puppet.com",
"affectedData": [
{
"vendor": "Puppet",
"product": "Puppet Agent",
"versions": [
{
"status": "affected",
"version": "Introduced in 1.3.0, fixed in 1.6.0"
}
]
}
]
}
],
"published": "2017-12-06T15:29:00.217",
"references": [
{
"url": "https://puppet.com/security/cve/cve-2016-5713",
"tags": [
"Vendor Advisory"
],
"source": "security@puppet.com"
},
{
"url": "https://puppet.com/security/cve/cve-2016-5713",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet runs. This could allow unauthorized code to be loaded. This bug was first introduced in Puppet Agent 1.3.0."
},
{
"lang": "es",
"value": "Las versiones de Puppet Agent anteriores a la 1.6.0 incluían una versión del agente Puppet Execution Protocol (PXP) que pasaba variables del entorno a ejecuciones Puppet. Esto podría permitir la carga de código no autorizado. Este error fue introducido por primera vez en Puppet Agent 1.3.0."
}
],
"lastModified": "2026-06-17T00:49:55.027",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:puppet:puppet_agent:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AAE84DE0-1FFF-43FE-AE90-59FCA9444C9F",
"versionEndExcluding": "1.6.0",
"versionStartIncluding": "1.3.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@puppet.com"
}