QID 379095

Date Published: 2023-12-06

QID 379095: Splunk Universal Forwarder Multiple Vulnerabilities (SVD-2023-1107)

Splunk Universal Forwarders provide reliable, secure data collection from remote sources and forward that data into Splunk software for indexing and consolidation.

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Splunk Universal Forwarder.

Affected Versions:
Splunk Universal Forwarder versions from 9.0.0 to 9.0.6
Splunk Universal Forwarder versions from 9.1.0 to 9.1.1

QID Detection Logic (Authenticated):
Windows: This QID checks for installed vulnerable version of Splunk Universal Forwarder using registry "HKLM\SYSTEM\CurrentControlSet\Services\SplunkForwarder"

Successful exploitation of this vulnerability may affects confidentiality, integrity and availability.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to latest release SVD-2023-1107 for updates pertaining to these vulnerabilities.
    Vendor References

    CVEs related to QID 379095

    Software Advisories
    Advisory ID Software Component Link
    SVD-2023-1107 URL Logo advisory.splunk.com/advisories/SVD-2023-1107