Cyber Resilience

CVE-2023-2530

Puppet Enterprise 2021.7.0 – 2021.7.3

Published
07 June 2023
Modified
26 August 2025
Patch / advisory
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.011 63th percentile
Risk Priority 79 floored blend · peak EPSS

Summary

CVE-2023-2530 is a critical-severity an unspecified weakness vulnerability in Puppet Puppet Enterprise. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 37% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

A privilege escalation vulnerability that enables remote code execution was identified in the orchestration service. The issue carries a CVSS 3.1 base score of 9.8 and affects Puppet Orchestrator, as indicated by the vendor security advisories published for CVE-2023-2530.

Unauthenticated remote attackers can exploit the flaw over the network without user interaction. Successful exploitation grants full confidentiality, integrity, and availability impact, allowing an adversary to execute arbitrary code with elevated privileges on the affected system.

Vendor advisories published by Puppet at the referenced URLs describe the issue and direct customers to available patches and remediation guidance for the orchestration service.

The associated EPSS score rose from a low baseline to a peak of 0.0776 on 2026-04-03 before receding to its current value of 0.0207, indicating a temporary increase in observed exploitation interest after disclosure.

EU & UK References

Vulnerability Data

A privilege escalation allowing remote code execution was discovered in the orchestration service.

CWE(s)

Related Threats

CVEs Like This One

CVE-2025-5459Same product: Puppet Puppet Enterprise
CVE-2023-5309Same product: Puppet Puppet Enterprise
CVE-2023-1894Same product: Puppet Puppet Enterprise
CVE-2023-5255Same product: Puppet Puppet Enterprise
CVE-2023-5214Same vendor: Puppet

Affected Assets

puppet
puppet enterprise
2023.0, 2023.1.0 · 2021.7.0 — 2021.7.3

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References