CVE-2018-6515
published 2018-06-11CVE-2018-6515: Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Windows only, with a specially crafted…
PriorityP337high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
0.85%
54.0th percentile
Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Windows only, with a specially crafted configuration file an attacker could get pxp-agent to load arbitrary code with privilege escalation.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet | — | — |
| puppet | puppet | >= 1.10.0 < 1.10.13 | 1.10.13 |
| puppet | puppet | >= 5.3.0 < 5.3.7 | 5.3.7 |
| puppet | puppet | >= 5.5.0 < 5.5.2 | 5.5.2 |
| puppet | puppet_agent | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5xw6-x436-6c39: Puppet Agent 1
ghsa_unreviewed·2022-05-14
CVE-2018-6515 [HIGH] CWE-20 GHSA-5xw6-x436-6c39: Puppet Agent 1
Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Windows only, with a specially crafted configuration file an attacker could get pxp-agent to load arbitrary code with privilege escalation.
Red Hat
puppet-agent: pxp-agent attempts to configure OpenSSL from uncontrolled location
vendor_redhat·2018-06-07·CVSS 7.8
CVE-2018-6515 [HIGH] puppet-agent: pxp-agent attempts to configure OpenSSL from uncontrolled location
puppet-agent: pxp-agent attempts to configure OpenSSL from uncontrolled location
Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Windows only, with a specially crafted configuration file an attacker could get pxp-agent to load arbitrary code with privilege escalation.
Statement: This issue did not affect the versions of puppet-agent as shipped with Red Hat Satellite 6 as this issue is specific to Windows platform only.
Package: puppet-agent (Red Hat Satellite 6) - Not affected
Debian
CVE-2018-6515: puppet - Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Pup...
vendor_debian·2018·CVSS 7.8
CVE-2018-6515 [HIGH] CVE-2018-6515: puppet - Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Pup...
Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Windows only, with a specially crafted configuration file an attacker could get pxp-agent to load arbitrary code with privilege escalation.
Scope: local
bullseye: resolved
No detection rules found.
No public exploits indexed.
2018-06-11
Published