CVE-2022-43571
HIGHAuthenticated RCE in Splunk (SimpleXML dashboard PDF generation)
Title source: metasploitDescription
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation component.
Exploits (2)
metasploit
WORKING POC
EXCELLENT
by Maksim Rogov, Danylo Dmytriiev, psytester · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/splunk_auth_rce_cve_2022_43571.rb
Scores
CVSS v3
8.8
EPSS
0.7521
EPSS Percentile
98.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-94
Status
published
Products (2)
splunk/splunk
8.1.0 - 8.1.12
splunk/splunk_cloud_platform
< 9.0.2209
Published
Nov 03, 2022
Tracked Since
Feb 18, 2026