CVE-2022-32158

CRITICAL

Splunk < 9.0 - Unauthenticated Arbitrary Code Execution via Deployment Server

Title source: llm
STIX 2.1

Description

Splunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients through the deployment server. An attacker that compromised a Universal Forwarder endpoint could use the vulnerability to execute arbitrary code on all other Universal Forwarder endpoints subscribed to the deployment server.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_confirm
https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/Updates

Scores

CVSS v3 9.0
EPSS 0.0122
EPSS Percentile 79.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-284
Status published
Products (1)
splunk/splunk < 9.0
Published Jun 15, 2022
Tracked Since Feb 18, 2026