AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-40596

HIGH · CVSS 7 EPSS 0.16%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-08-30 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2023-40596
Severity
HIGH
CVSS
7
EPSS
0.16%
Windows OpenSSL

Original NVD Description

In Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1, a dynamic link library (DLL) that ships with Splunk Enterprise references an insecure path for the OPENSSLDIR build definition. An attacker can abuse this reference and subsequently install malicious code to achieve privilege escalation on the Windows machine.