SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-22164

In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker can use investigation attachments to perform a denial of service (DoS) to the Investigation.

MEDIUM 4.3EPSS 0.46%

Does this matter?

Lower severity and a low EPSS score (0.46%). Track it; it rarely justifies an emergency change on its own.

Description

In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker can use investigation attachments to perform a denial of service (DoS) to the Investigation. The attachment endpoint does not properly limit the size of the request which lets an attacker cause the Investigation to become inaccessible.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
EPSS
0.46% probability · 39th percentile
CISA KEV
Not listed
Weakness
CWE-400, CWE-770
Affected
splunk/enterprise security
Source
prodsec@splunk.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.