CVE-2023-40596

EUVD-2023-45154
In Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1, a dynamic link library (DLL) that ships with Splunk Enterprise references an insecure path for the OPENSSLDIR build definition. An attacker can abuse this reference and subsequently install malicious code to achieve privilege escalation on the Windows machine.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7 HIGH
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
SplunkCNA
7 HIGH
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
Affected Products (NVD)
VendorProductVersion
splunksplunk
8.2.12 <
𝑥
< 8.2.12
splunksplunk
9.0.6 <
𝑥
< 9.0.6
splunksplunk
9.1.1 <
𝑥
< 9.1.1
splunksplunk
8.2.0 ≤
𝑥
< 8.2.12
splunksplunk
9.0.0 ≤
𝑥
< 9.0.6
splunksplunk
9.1.0
𝑥
= Vulnerable software versions