CVE-2022-43571 is a high-severity vulnerability affecting Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, as well as Splunk Cloud Platform. It allows an authenticated user to execute arbitrary code via the dashboard PDF generation component. The vulnerability has a CVSS score of 8.8 (High), indicating a network-based attack with low complexity, requiring only low privileges, and leading to high impact on confidentiality, integrity, and availability. While not listed on the KEV catalog, a Metasploit module exists for this vulnerability, and it has garnered significant community discussion and media coverage, suggesting active awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.1.0, < 8.1.12CPE matchmatch criteria | cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* | ||
>= 8.2.0, < 8.2.9CPE matchmatch criteria | cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* | ||
>= 9.0.0, < 9.0.2CPE matchmatch criteria | cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* | ||
< 9.0.2209CPE matchmatch criteria | cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:* | ||
>= 8.1, < 8.1.12CPE match | cpe:2.3:a:splunk:splunk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.