CVE-2022-43567 is a high-severity vulnerability affecting Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2. An authenticated attacker can achieve remote code execution by sending specially crafted requests to the mobile alerts feature within the Splunk Secure Gateway app. With a CVSS score of 8.8 (HIGH), this vulnerability allows for full compromise of confidentiality, integrity, and availability with low attack complexity and no user interaction required. While there is no known public exploit code or active exploitation, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.1.0, < 8.1.12CPE matchmatch criteria | cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* | ||
>= 8.2.0, < 8.2.9CPE matchmatch criteria | cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* | ||
>= 9.0.0, < 9.0.2CPE matchmatch criteria | cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* | ||
< 9.0.2205CPE matchmatch criteria | cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:* | ||
>= 8.1, < 8.1.12CPE match | cpe:2.3:a:splunk:splunk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.