QID 379122
Date Published: 2024-02-27
QID 379122: Splunk Universal Forwarder Insecure Remote Login Vulnerability (SVD-2022-0605)
Splunk Universal Forwarders provide reliable, secure data collection from remote sources and forward that data into Splunk software for indexing and consolidation.
In Splunk universal forwarder versions before 9.0, management services are available remotely by default. When not required, it introduces a potential exposure, but it is not a vulnerability. If exposed, we recommend each customer assess the potential severity specific to your environment. In 9.0, the universal forwarder now binds the management port to localhost preventing remote logins by default.
Affected Versions:
Splunk Universal Forwarder before version 9.0.0
QID Detection Logic (Authenticated):
Windows: This QID checks for installed vulnerable version of Splunk Universal Forwarder using registry "HKLM\SYSTEM\CurrentControlSet\Services\SplunkForwarder"
Successful exploitation of this vulnerability allows attackers to attempt remote login by default.
CVEs related to QID 379122
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2022-0605 |
|