CVE-2021-3422
Summary
| CVE | CVE-2021-3422 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-25 19:15:00 UTC |
| Updated | 2022-04-11 19:51:00 UTC |
| Description | The lack of validation of a key-value field in the Splunk-to-Splunk protocol results in a denial-of-service in Splunk Enterprise instances configured to index Universal Forwarder traffic. The vulnerability impacts Splunk Enterprise versions before 7.3.9, 8.0 versions before 8.0.9, and 8.1 versions before 8.1.3. It does not impact Universal Forwarders. When Splunk forwarding is secured using TLS or a Token, the attack requires compromising the certificate or token, or both. Implementation of either or both reduces the severity to Medium. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Team82: Splunk Enterprise Indexer, Forwarder Vulnerability Patched | MISC | claroty.com | |
| SVD-2022-0301 | Splunk | MISC | www.splunk.com | |
| Team82: Splunk Enterprise Indexer, Forwarder Vulnerability Patched | MISC | claroty.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Sharon Brizinov and Tal Keren of Claroty
Legacy QID Mappings
- 730494 Splunk Enterprise Denial of Service (DoS) Vulnerability (SVD-2022-0301)