Cyber Resilience

CVE-2023-2530

Critical

Published: 07 June 2023

Published
07 June 2023
Modified
26 August 2025
KEV Added
Patch
CVSS Score v3.1 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0207 84.3th percentile
Risk Priority 21 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2023-2530 is a critical-severity an unspecified weakness vulnerability in Puppet Puppet Enterprise. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 15.7% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

Deeper analysis

A privilege escalation vulnerability that enables remote code execution was identified in the orchestration service. The issue carries a CVSS 3.1 base score of 9.8 and affects Puppet Orchestrator, as indicated by the vendor security advisories published for CVE-2023-2530.

Unauthenticated remote attackers can exploit the flaw over the network without user interaction. Successful exploitation grants full confidentiality, integrity, and availability impact, allowing an adversary to execute arbitrary code with elevated privileges on the affected system.

Vendor advisories published by Puppet at the referenced URLs describe the issue and direct customers to available patches and remediation guidance for the orchestration service.

The associated EPSS score rose from a low baseline to a peak of 0.0776 on 2026-04-03 before receding to its current value of 0.0207, indicating a temporary increase in observed exploitation interest after disclosure.

EU & UK References

Vulnerability details

A privilege escalation allowing remote code execution was discovered in the orchestration service.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

puppet
puppet enterprise
2023.0, 2023.1.0 · 2021.7.0 — 2021.7.3

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References