CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.5. See the original NVD description below for full technical details.
CVE
CVE-2023-40598
Severity
HIGH
CVSS
8.5
EPSS
0.60%
Original NVD Description
In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a legacy internal function. The attacker can use this internal function to insert code into the Splunk platform installation directory. From there, a user can execute arbitrary code on the Splunk platform Instance.
Related CVEs
Other vulnerabilities affecting the same vendor(s)