Lucene search

K
cvelistMitreCVELIST:CVE-2013-1654
HistoryMar 20, 2013 - 4:00 p.m.

CVE-2013-1654

2013-03-2016:00:00
mitre
www.cve.org
5

AI Score

6.3

Confidence

Low

EPSS

0.008

Percentile

81.4%

Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol between client and master, which allows remote attackers to conduct SSLv2 downgrade attacks against SSLv3 sessions via unspecified vectors.