PT-2022-21124 · Splunk · Universal Forwarder

Chris Green

·

Published

2022-06-15

·

Updated

2022-06-24

·

CVE-2022-32155

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Universal Forwarder versions prior to 9.0
Description The universal forwarder has management services available remotely by default in versions before 9.0, which can introduce a potential exposure if not required. In version 9.0, the management port is bound to localhost by default, preventing remote logins. Customers are recommended to assess the potential severity of this exposure specific to their environment.
Recommendations For Universal Forwarder versions prior to 9.0, if management services are not required, set disableDefaultPort = true in server.conf or allowRemoteLogin = never in server.conf or mgmtHostPort = localhost in web.conf to disable remote management services.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-32155

Affected Products

Universal Forwarder