{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-06T03:30:12.143","vulnerabilities":[{"cve":{"id":"CVE-2016-3728","sourceIdentifier":"secalert@redhat.com","published":"2016-05-20T14:59:04.387","lastModified":"2025-04-12T10:46:40.837","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Eval injection vulnerability in tftp_api.rb in the TFTP module in the Smart-Proxy in Foreman before 1.10.4 and 1.11.x before 1.11.2 allows remote attackers to execute arbitrary code via the PXE template type portion of the PATH_INFO to tftp/."},{"lang":"es","value":"Vulnerabilidad en la inyección Eval en tftp_api.rb en el módulo TFTP en el Smart-Proxy en Foreman en versiones anteriores 1.10.4 y 1.11.x en versiones anteriores a 1.11.2 permite a atacantes remotos ejecutar un código arbitrario a través de la plantilla de porción tipo del PATH_INFO para tftp/."}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:theforeman:foreman:1.11.0:*:*:*:*:*:*:*","matchCriteriaId":"D4197DE0-AEB1-41CA-9264-22C29CCD7102"},{"vulnerable":true,"criteria":"cpe:2.3:a:theforeman:foreman:1.11.0:rc1:*:*:*:*:*:*","matchCriteriaId":"E058208D-14B4-4D86-9B5D-57383FC5D5ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:theforeman:foreman:1.11.0:rc2:*:*:*:*:*:*","matchCriteriaId":"564712BC-DB56-4B47-936B-C0E326EB38B2"},{"vulnerable":true,"criteria":"cpe:2.3:a:theforeman:foreman:1.11.0:rc3:*:*:*:*:*:*","matchCriteriaId":"1138BC97-DAB7-40C6-91C3-3E237FFAEBFD"},{"vulnerable":true,"criteria":"cpe:2.3:a:theforeman:foreman:1.11.1:*:*:*:*:*:*:*","matchCriteriaId":"87836834-0E63-4756-B67D-1C37EC5BCDF4"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:theforeman:foreman:1.10.3:*:*:*:*:*:*:*","matchCriteriaId":"F469D8A8-C09F-471B-AB46-05EB78D23CA1"}]}]}],"references":[{"url":"http://projects.theforeman.org/issues/14931","source":"secalert@redhat.com"},{"url":"http://theforeman.org/security.html#2016-3728","source":"secalert@redhat.com","tags":["Vendor Advisory"]},{"url":"http://www.openwall.com/lists/oss-security/2016/05/19/2","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHBA-2016:1501","source":"secalert@redhat.com"},{"url":"https://github.com/theforeman/smart-proxy/commit/eef532aa668d656b9d61d9c6edf7c2505f3f43c7","source":"secalert@redhat.com"},{"url":"http://projects.theforeman.org/issues/14931","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://theforeman.org/security.html#2016-3728","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"http://www.openwall.com/lists/oss-security/2016/05/19/2","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHBA-2016:1501","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/theforeman/smart-proxy/commit/eef532aa668d656b9d61d9c6edf7c2505f3f43c7","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}