← Vulnerability feed

Vulnerability record · CVE-2018-6514 · published 11 June 2018

CVE-2018-6514: Puppet untrusted search path vulnerability

Puppet · Puppet

In Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Puppet Agent 5.5.x prior to 5.5.2, Facter on Windows is vulnerable to a DLL preloading attack, which could lead to a privilege escalation.

7.8 CVSS 3.0 High EPSS 0.85% · top 43.6% CWE-426 · Untrusted search path
7.8CVSS 3.0 base score, v2 6.8
0.85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Puppet Agent 5.5.x prior to 5.5.2, Facter on Windows is vulnerable to a DLL preloading attack, which could lead to a privilege escalation.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-6514 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-2785Puppet improper access control vulnerabilityPuppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass i…EPSS 2.9%9.0CVE-2013-1640Puppet vulnerabilityThe (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Pup…EPSS 4.9%8.8CVE-2021-27021Puppet sql injection vulnerabilityA flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query.EPSS 1.3%8.8CVE-2018-6513Puppet untrusted search path vulnerabilityPuppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x prior to 2018.1.1, Puppet Age…EPSS 1.1%8.2CVE-2017-2295Puppet deserialization of untrusted data vulnerabilityVersions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. …EPSS 2.4%7.8CVE-2018-6515Puppet improper input validation vulnerabilityPuppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Windows only, with a specially craf…EPSS 0.85%7.5CVE-2013-3567Puppet improper input validation vulnerabilityPuppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to …EPSS 3.4%7.5CVE-2013-1655Puppet improper input validation vulnerabilityPuppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via vectors re…EPSS 4.6%

Source: NIST National Vulnerability Database (record CVE-2018-6514), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.