CVE-2023-4571 is a high-severity vulnerability affecting Splunk IT Service Intelligence (ITSI) versions below 4.13.3, 4.15.3, and 4.17.1. It allows for the injection of ANSI escape codes into ITSI log files, which can lead to arbitrary code execution when a vulnerable terminal application reads these logs locally. The attack requires user interaction and a terminal that interprets ANSI escape codes, with an overall CVSS score of 8.6. While not directly impacting Splunk ITSI, the indirect impact can be significant depending on terminal permissions. There is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.13.0, < 4.13.3CPE matchmatch criteria | cpe:2.3:a:splunk:it_service_intelligence:*:*:*:*:*:*:*:* | ||
>= 4.15.0, < 4.15.3CPE matchmatch criteria | cpe:2.3:a:splunk:it_service_intelligence:*:*:*:*:*:*:*:* | ||
4.17.0CPE matchmatch criteria | cpe:2.3:a:splunk:it_service_intelligence:4.17.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.