CVE-2013-4965: Puppet Enterprise

Medium severity, CVSS 5.0. EPSS: 1.3% chance of exploitation in the next 30 days.

Puppet Enterprise before 3.1.0 does not properly restrict the number of authentication attempts by a console account, which makes it easier for remote attackers to bypass intended access restrictions via a brute-force attack.

Affected products

  • Puppet Puppet Enterprise: up to and including 3.0.1; version 3.0.0 only

Published 2013-10-25. Last modified 2026-06-16.