logo

Splunk Patches Indexer Vulnerability Discovered by Team82

ID: ef5ae1fa-9300-5e32-b810-d9c7fd69ba38

STIX ID: report--ef5ae1fa-9300-5e32-b810-d9c7fd69ba38

Feed Name: Claroty Team82

Threat Score
75/100

Date Published: 2023-08-22

Date Updated: 2026-04-17

Author: Sharon Brizinov

...
...

Team82 disclosed CVE-2021-3422, a high-severity vulnerability in Splunk Enterprise indexers and forwarders where improper validation of a dynamic field in the S2S v3 protocol allows crafted packets to trigger an out-of-bounds read; attackers can exfiltrate splunkd process memory or crash splunkd (denial-of-service). Splunk has released patches and recommends enabling TLS authentication or forwarder tokens to mitigate the risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.