PT-2022-26975 · Splunk · Splunk Enterprise

Published

2022-11-04

·

Updated

2022-11-08

·

CVE-2022-43572

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Splunk Enterprise versions prior to 8.2.9 Splunk Enterprise versions prior to 8.1.12 Splunk Enterprise versions prior to 9.0.2
Description The issue occurs when a malformed file is sent through the Splunk-to-Splunk (S2S) or HTTP Event Collector (HEC) protocols to an indexer, resulting in a blockage or denial-of-service that prevents further indexing.
Recommendations For versions prior to 8.2.9, update to version 8.2.9 or later to resolve the issue. For versions prior to 8.1.12, update to version 8.1.12 or later to resolve the issue. For versions prior to 9.0.2, update to version 9.0.2 or later to resolve the issue.

Fix

DoS

Resource Exhaustion

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2022-43572

Affected Products

Splunk Enterprise