SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-10694

The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password.

CRITICAL 9.8EPSS 1.09%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.09%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL, there is an overlooked default password for the admin user. This was resolved in Puppet Enterprise 2019.0.3 and 2018.1.9.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.09% probability · 63th percentile
CISA KEV
Not listed
Weakness
CWE-798
Affected
puppet/puppet enterprise
Source
security@puppet.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.