CVE-2011-3872

Puppet 2.6.x < 2.6.12 and 2.7.x < 2.7.6 - Certificate Spoofing via X.509 Subject Alternative Name Field

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-3872. PoCs published by puppetlabs-toy-chest.

AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2011-3872, which involves Puppet's certificate validation bypass. The code includes custom Facter facts and Puppet functions to manipulate certificate settings and migration states.

Description

Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to the X.509 Subject Alternative Name field of the certificate, which allows remote attackers to spoof a Puppet master via a man-in-the-middle (MITM) attack against an agent that uses an alternate DNS name for the master, aka "AltNames Vulnerability."

Exploits (1)

nomisec WORKING POC 5 stars
by puppetlabs-toy-chest · poc
https://github.com/puppetlabs-toy-chest/puppetlabs-cve20113872

This repository contains a proof-of-concept exploit for CVE-2011-3872, which involves Puppet's certificate validation bypass. The code includes custom Facter facts and Puppet functions to manipulate certificate settings and migration states.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Puppet (versions affected by CVE-2011-3872)
No auth needed
Prerequisites: Access to a Puppet agent or server environment · Ability to modify or influence certificate-related configurations
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46550
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1238-2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/70970
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46578
Various Sources x_refsource_confirm
https://puppet.com/security/cve/cve-2011-3872
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46934
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/50356
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46964
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1238-1

Scores

EPSS 0.0278
EPSS Percentile 86.2%

Details

CWE
CWE-20
Status published
Products (24)
puppet/puppet 2.6.0
puppet/puppet 2.6.1
puppet/puppet 2.6.2
puppet/puppet 2.6.3
puppet/puppet 2.6.4
puppet/puppet 2.6.5
puppet/puppet 2.6.6
puppet/puppet 2.6.7
puppet/puppet 2.6.8
puppet/puppet 2.6.9
... and 14 more
Published Oct 27, 2011
Tracked Since Feb 18, 2026