CVE-2023-5255
Denial of Service for Revocation of Auto Renewed Certificates
Severity Score
7.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track
*SSVC
Descriptions
For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.
Para los certificados que utilizan la función de renovación automática en Puppet Server, existe una falla que impide que los certificados sean revocados.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-09-28 CVE Reserved
- 2023-10-03 CVE Published
- 2024-09-19 CVE Updated
- 2024-10-09 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-404: Improper Resource Shutdown or Release
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Puppet Search vendor "Puppet" | Puppet Search vendor "Puppet" for product "Puppet" | 2023.3 Search vendor "Puppet" for product "Puppet" and version "2023.3" | enterprise |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Server Search vendor "Puppet" for product "Puppet Server" | 8.2.0 Search vendor "Puppet" for product "Puppet Server" and version "8.2.0" | - |
Affected
| ||||||
Puppet Search vendor "Puppet" | Puppet Server Search vendor "Puppet" for product "Puppet Server" | 8.2.1 Search vendor "Puppet" for product "Puppet Server" and version "8.2.1" | - |
Affected
|