PT-2022-3396 · Splunk · Universal Forwarder+1
Martin Müller
+2
·
Published
2022-06-14
·
Updated
2022-06-24
·
CVE-2022-32157
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Splunk Enterprise versions prior to 9.0
Description
The issue is related to the lack of an authentication procedure in Splunk Enterprise deployment servers, allowing unauthenticated downloading of forwarder bundles. This can potentially enable a remote attacker to elevate their privileges. Remediation requires updating the deployment server to version 9.0 and configuring authentication for deployment servers and clients. Once enabled, deployment servers can only manage Universal Forwarder versions 9.0 and higher. Although Universal Forwarders are not directly affected, updating them to version 9.0 or higher is necessary prior to enabling the remediation.
Recommendations
Update the deployment server to version 9.0.
Configure authentication for deployment servers and clients.
Update all Universal Forwarders managed by the deployment server to version 9.0 or higher prior to enabling the remediation.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Splunk Enterprise
Universal Forwarder