CVE-2023-40598 — Command Injection in Cloud
CWE-77 — Command InjectionCWE-306 — Missing Authentication for Critical Function3 documents3 sources
Severity
8.8HIGHNVD
CNA8.5
EPSS
0.1%
top 75.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 30
Description
In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a legacy internal function. The attacker can use this internal function to insert code into the Splunk platform installation directory. From there, a user can execute arbitrary code on the Splunk platform Instance.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9