Splunk Patches Indexer Vulnerability Discovered by Team82
ID: ef5ae1fa-9300-5e32-b810-d9c7fd69ba38
STIX ID: report--ef5ae1fa-9300-5e32-b810-d9c7fd69ba38
Feed Name: Claroty Team82
Threat Score
Team82 disclosed CVE-2021-3422, a high-severity vulnerability in Splunk Enterprise indexers and forwarders where improper validation of a dynamic field in the S2S v3 protocol allows crafted packets to trigger an out-of-bounds read; attackers can exfiltrate splunkd process memory or crash splunkd (denial-of-service). Splunk has released patches and recommends enabling TLS authentication or forwarder tokens to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
