{"api_version":"1","generated_at":"2026-07-23T22:22:37+00:00","cve":"CVE-2021-31559","urls":{"html":"https://cve.report/CVE-2021-31559","api":"https://cve.report/api/cve/CVE-2021-31559.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-31559","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-31559"},"summary":{"title":"CVE-2021-31559","description":"A crafted request bypasses S2S TCP Token authentication writing arbitrary events to an index in Splunk Enterprise Indexer 8.1 versions before 8.1.5 and 8.2 versions before 8.2.1. The vulnerability impacts Indexers configured to use TCPTokens. It does not impact Universal Forwarders.","state":"PUBLIC","assigner":"prodsec@splunk.com","published_at":"2022-05-06 17:15:00","updated_at":"2022-10-25 16:42:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"https://www.splunk.com/en_us/product-security/announcements/svd-2022-0503.html","name":"https://www.splunk.com/en_us/product-security/announcements/svd-2022-0503.html","refsource":"MISC","tags":[],"title":"SVD-2022-0503 | Splunk","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-31559","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-31559","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"31559","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"splunk","cpe5":"splunk","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"31559","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"splunk","cpe5":"splunk","cpe6":"8.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-31559","qid":"378041","title":"Splunk Enterprise S2S TCP Token Vulnerability (SVD-2022-0503)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2021-31559","STATE":"PUBLIC","ASSIGNER":"prodsec@splunk.com","TITLE":"S2S TcpToken authentication bypass"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Splunk","product":{"product_data":[{"product_name":"Splunk Enterprise","version":{"version_data":[{"version_value":"8.2 version(s) before 8.2.1"},{"version_value":"Version(s) before 8.1.5"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-288"}]}]},"references":{"reference_data":[{"url":"https://www.splunk.com/en_us/product-security/announcements/svd-2022-0503.html","refsource":"MISC","name":"https://www.splunk.com/en_us/product-security/announcements/svd-2022-0503.html"}]},"description":{"description_data":[{"lang":"eng","value":"A crafted request bypasses S2S TCP Token authentication writing arbitrary events to an index in Splunk Enterprise Indexer 8.1 versions before 8.1.5 and 8.2 versions before 8.2.1. The vulnerability impacts Indexers configured to use TCPTokens. It does not impact Universal Forwarders."}]},"impact":{"cvss":{"baseScore":"7.5","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"}},"generator":{"engine":"advisoriator"},"source":{"advisory":"SVD-2022-0503","discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2022-05-06 17:15:00","lastModifiedDate":"2022-10-25 16:42:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.1.0","versionEndExcluding":"8.1.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:splunk:splunk:8.2.0:*:*:*:enterprise:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"31559","Ordinal":"220411","Title":"CVE-2021-31559","CVE":"CVE-2021-31559","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"31559","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}