7.5
CVSSv3

CVE-2021-31559

Published: 06/05/2022 Updated: 25/10/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

A crafted request bypasses S2S TCP Token authentication writing arbitrary events to an index in Splunk Enterprise Indexer 8.1 versions prior to 8.1.5 and 8.2 versions prior to 8.2.1. The vulnerability impacts Indexers configured to use TCPTokens. It does not impact Universal Forwarders.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

splunk splunk

splunk splunk 8.2.0