CVE-2025-20388

In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.7, and 9.3.2411.116, a user who holds a role that contains the high privilege capability `change_authentication` could enumerate internal IP addresses and network ports when adding new search peers to a Splunk search head in a distributed environment.
SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.7 LOW
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
ciscoCNA
2.7 LOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
VendorProductVersion
splunksplunk
9.2.0 ≤
𝑥
< 9.2.10
splunksplunk
9.3.0 ≤
𝑥
< 9.3.8
splunksplunk
9.4.0 ≤
𝑥
< 9.4.6
splunksplunk
10.0.0
splunksplunk_cloud_platform
9.3.2411 ≤
𝑥
< 9.3.2411.116
splunksplunk_cloud_platform
10.0.2503 ≤
𝑥
< 10.0.2503.6
splunksplunk_cloud_platform
10.1.2507 ≤
𝑥
< 10.1.2507.4
𝑥
= Vulnerable software versions