CVE-2023-2530
Published: 07 June 2023
Summary
CVE-2023-2530 is a critical-severity an unspecified weakness vulnerability in Puppet Puppet Enterprise. Its CVSS base score is 9.8 (Critical).
Operationally, ranked in the top 15.7% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
Deeper analysis
A privilege escalation vulnerability that enables remote code execution was identified in the orchestration service. The issue carries a CVSS 3.1 base score of 9.8 and affects Puppet Orchestrator, as indicated by the vendor security advisories published for CVE-2023-2530.
Unauthenticated remote attackers can exploit the flaw over the network without user interaction. Successful exploitation grants full confidentiality, integrity, and availability impact, allowing an adversary to execute arbitrary code with elevated privileges on the affected system.
Vendor advisories published by Puppet at the referenced URLs describe the issue and direct customers to available patches and remediation guidance for the orchestration service.
The associated EPSS score rose from a low baseline to a peak of 0.0776 on 2026-04-03 before receding to its current value of 0.0207, indicating a temporary increase in observed exploitation interest after disclosure.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-34010
Vulnerability details
A privilege escalation allowing remote code execution was discovered in the orchestration service.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.