QID 730310

Date Published: 2021-12-27

QID 730310: Splunk Enterprise and Light Denial of Service (DoS) Vulnerability (SP-CAAAPSV) (SPL-129207)

Splunk captures, indexes, and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards, and visualizations.

CVE-2016-2182: The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to cause a denial of service.

Affected Versions:
Splunk Enterprise versions 6.5.0
Splunk Enterprise versions 6.4.x before 6.4.5
Splunk Enterprise versions 6.3.x before 6.3.8
Splunk Enterprise versions 6.2.x before 6.2.12
Splunk Enterprise versions 6.1.x before 6.1.12
Splunk Enterprise versions 6.0.x before 6.0.13
Splunk Light versions prior to 6.5.0

QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable versions of Splunk Enterprise and Light by making a request to the account/login/ URL.

Successful exploitation of this vulnerability may allow an remote attacker to stop or crash the splunk service.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to latest release SP-CAAAPSV for updates pertaining to these vulnerabilities.

    CVEs related to QID 730310

    Software Advisories
    Advisory ID Software Component Link
    SP-CAAAPSV (SPL-129207) URL Logo www.splunk.com/en_us/product-security/announcements-archive/SP-CAAAPSV.html