CVE-2021-3422
Last modified
CVE-2021-3422 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The lack of validation of a key-value field in the Splunk-to-Splunk protocol results in a denial-of-service in Splunk Enterprise instances configured to index Universal Forwarder traffic. The vulnerability impacts Splunk Enterprise versions before 7.3.9, 8.0 versions before 8.0.9, and 8.1 versions before 8.1.3. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
The lack of validation of a key-value field in the Splunk-to-Splunk protocol results in a denial-of-service in Splunk Enterprise instances configured to index Universal Forwarder traffic. The vulnerability impacts Splunk Enterprise versions before 7.3.9, 8.0 versions before 8.0.9, and 8.1 versions before 8.1.3. It does not impact Universal Forwarders. When Splunk forwarding is secured using TLS or a Token, the attack requires compromising the certificate or token, or both. Implementation of either or both reduces the severity to Medium.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Splunk | Splunk | < 7.3.9 |
| Splunk | Splunk | >= 8.0, < 8.0.9 |
| Splunk | Splunk | >= 8.1, < 8.1.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-3422?
How severe is CVE-2021-3422?
How do I fix CVE-2021-3422?
Are you affected by CVE-2021-3422?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
