CVE-2014-3251 describes a race condition vulnerability in the MCollective aes_security plugin, affecting Puppet Enterprise before 3.3.0 and MCollective before 2.5.3. This flaw allows local users to establish unauthorized MCollective connections due to improper validation of new server certificates against the CA certificate. With a CVSS score of 4.4 (AV:L/AC:M/Au:N/C:P/I:P/A:P), it indicates a low-severity vulnerability requiring local access and medium attack complexity, potentially leading to partial confidentiality, integrity, and availability compromise. There is no known exploit intelligence, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.2.0CPE matchmatch criteria | cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:puppetlabs:mcollective:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.