PCP Broker Message Header Size Validation Vulnerability

PCP Broker Message Header Size Validation Vulnerability

CVE-2016-9686 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:N/A:P

The Puppet Communications Protocol (PCP) Broker incorrectly validates message header sizes. An attacker could use this to crash the PCP Broker, preventing commands from being sent to agents. This is resolved in Puppet Enterprise 2016.4.3 and 2016.5.2.

Learn more about our Web Application Penetration Testing UK.