Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 3 |
CVE-ID | CVE-2023-22940 CVE-2023-22941 CVE-2023-22938 |
CWE-ID | CWE-20 CWE-248 CWE-285 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software |
Splunk Enterprise Server applications / IDS/IPS systems, Firewalls and proxy servers Splunk Cloud Platform Server applications / IDS/IPS systems, Firewalls and proxy servers |
Vendor | Splunk Inc. |
Security Bulletin
This security bulletin contains information about 3 vulnerabilities.
EUVDB-ID: #VU77075
Risk: Medium
CVSSv3.1: 5.5 [CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-22940
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the SPL Command Safeguards Bypass within the "collect" SPL Command Aliases. A remote user can gain access to sensitive information on the system.
MitigationInstall updates from vendor's website.
Vulnerable software versionsSplunk Enterprise: 8.1.0 - 9.0.3
CPE2.3http://advisory.splunk.com/advisories/SVD-2023-0210
http://research.splunk.com/endpoint/ee69374a-d27e-4136-adac-956a96ff60fd
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected application in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU77074
Risk: Medium
CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-22941
CWE-ID:
CWE-248 - Uncaught Exception
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to uncaught exception in the "INGEST_EVAL" parameter. A remote user can pass specially crafted input to the application and perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Vulnerable software versionsSplunk Enterprise: 8.1.0 - 9.0.3
Splunk Cloud Platform: 9.0.2209
CPE2.3http://advisory.splunk.com/advisories/SVD-2023-0211
http://research.splunk.com/application/08978eca-caff-44c1-84dc-53f17def4e14/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected application in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU77068
Risk: Low
CVSSv3.1: 3.8 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-22938
CWE-ID:
CWE-285 - Improper Authorization
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to bypass the authorization mechanisms.
The vulnerability exists due to permissions validation failure in the "sendemail" REST API Endpoint. A remote user can send an email as the Splunk instance.
MitigationInstall updates from vendor's website.
Vulnerable software versionsSplunk Enterprise: 8.1.0 - 9.0.3
Splunk Cloud Platform: before 9.0.2212
CPE2.3 External linkshttp://advisory.splunk.com/advisories/SVD-2023-0208
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected application in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.