QID 730544
Date Published: 2022-07-04
QID 730544: Splunk Enterprise Improper Transport Layer Security (TLS) Certificate Validation (SVD-2022-0606)
Splunk captures, indexes, and correlates real-time data in a searchable repository from which it can generate graphs, reports, alerts, dashboards, and visualizations.
CVE-2022-32156: In Splunk Enterprise versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while connecting to a remote Splunk platform instance by default.
Affected Versions:
Splunk Enterprise versions prior to 9.0.0
NOTE:
Splunk peer communications configured properly with valid certificates are not vulnerable.
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable versions of Splunk Enterprise by making a request to the account/login/ URL.
Successful exploitation of this vulnerability may allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client.
CVEs related to QID 730544
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SVD-2022-0606 |
|