Puppet Enterprise before 3.1.0 does not properly restrict the number of authentication attempts by a console account, which makes it easier for remote attackers to bypass intended access restrictions via a brute-force attack.
Base Score: 5
Impact Score: 2.9
Exploitability Score: 10
cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:* versions up to 3.0.1 (inclusive)
View all (1 total)