ZeroHour

CVE-2022-43567

PoC
CVSS 3.1
8.8 high
EPSS
1%p68
Published
()
Modified
Description

In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can run arbitrary operating system commands remotely through the use of specially crafted requests to the mobile alerts feature in the Splunk Secure Gateway app.

Vendors
splunk
Products
splunk, splunk cloud platform
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.