PT-2022-3396 · Splunk · Universal Forwarder+1

Martin Müller

+2

·

Published

2022-06-14

·

Updated

2022-06-24

·

CVE-2022-32157

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Splunk Enterprise versions prior to 9.0
Description The issue is related to the lack of an authentication procedure in Splunk Enterprise deployment servers, allowing unauthenticated downloading of forwarder bundles. This can potentially enable a remote attacker to elevate their privileges. Remediation requires updating the deployment server to version 9.0 and configuring authentication for deployment servers and clients. Once enabled, deployment servers can only manage Universal Forwarder versions 9.0 and higher. Although Universal Forwarders are not directly affected, updating them to version 9.0 or higher is necessary prior to enabling the remediation.
Recommendations Update the deployment server to version 9.0. Configure authentication for deployment servers and clients. Update all Universal Forwarders managed by the deployment server to version 9.0 or higher prior to enabling the remediation.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04168
CVE-2022-32157

Affected Products

Splunk Enterprise
Universal Forwarder