CVE-2022-43567Deserialization of Untrusted Data in Enterprise

Severity
8.8HIGHNVD
EPSS
1.1%
top 22.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 4
Latest updateNov 5

Description

In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system commands remotely through the use of specially crafted requests to the mobile alerts feature in the Splunk Secure Gateway app.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5splunk/splunk_enterprise8.18.1.12+2
NVDsplunk/splunk8.1.08.1.12+2

🔴Vulnerability Details

2
GHSA
GHSA-768c-qx9v-r6h3: In Splunk Enterprise versions below 82022-11-05
CVEList
Remote Code Execution via the Splunk Secure Gateway application Mobile Alerts feature2022-11-04
CVE-2022-43567 — Deserialization of Untrusted Data | cvebase