« Volver al listado

CVE-2021-27018

Estado: ModificadaAlta (7.5)—

The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate authority to not be properly validated. This issue only affects clients that are configured to utilize Tenable.sc as the vulnerability data source.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-27018",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@puppet.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Puppet Remediate",
          "versions": [
            {
              "status": "affected",
              "version": "Affects Puppet Remediate prior to 2.0, resolved in 2.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-08-30T18:15:08.513",
  "references": [
    {
      "url": "https://puppet.com/security/cve/CVE-2021-27018",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@puppet.com"
    },
    {
      "url": "https://puppet.com/security/cve/CVE-2021-27018",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-295"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate authority to not be properly validated. This issue only affects clients that are configured to utilize Tenable.sc as the vulnerability data source."
    },
    {
      "lang": "es",
      "value": "Se ha detectado que el mecanismo lleva a cabo la comprobación de certificados tenía un fallo que resultaba que los certificados firmados por una autoridad de certificación interna no fueran comprobados apropiadamente. Este problema sólo afecta a clientes que están configurados para usar el archivo Tenable.sc como fuente de datos de vulnerabilidad."
    }
  ],
  "lastModified": "2026-06-17T03:44:08.267",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:puppet:remediate:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AB3AC2C1-DB7A-4BD7-9660-BA95799EB7D2",
              "versionEndExcluding": "2.0.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@puppet.com"
}