CVE-2024-36983
Estado: AnalizadaAlta (8.8)—
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an authenticated user could create an external lookup that calls a legacy internal function. The authenticated user could use this internal function to insert code into the Splunk platform installation directory. From there, the user could execute arbitrary code on the Splunk platform Instance.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.00%
- Percentil entre todas las CVEs puntuadas: 61
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-77
- CWE-77
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-36983",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-36983",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-07-02T20:10:58.843878Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "prodsec@splunk.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "prodsec@splunk.com",
"affectedData": [
{
"vendor": "Splunk",
"product": "Splunk Enterprise",
"versions": [
{
"status": "affected",
"version": "9.2",
"lessThan": "9.2.2",
"versionType": "custom"
},
{
"status": "affected",
"version": "9.1",
"lessThan": "9.1.5",
"versionType": "custom"
},
{
"status": "affected",
"version": "9.0",
"lessThan": "9.0.10",
"versionType": "custom"
}
]
},
{
"vendor": "Splunk",
"product": "Splunk Cloud Platform",
"versions": [
{
"status": "affected",
"version": "9.1.2312",
"lessThan": "9.1.2312.109",
"versionType": "custom"
},
{
"status": "affected",
"version": "9.1.2308",
"lessThan": "9.1.2308.207",
"versionType": "custom"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*"
],
"vendor": "splunk",
"product": "splunk",
"versions": [
{
"status": "affected",
"version": "9.2",
"lessThan": "9.2.2",
"versionType": "custom"
},
{
"status": "affected",
"version": "9.1",
"lessThan": "9.1.5",
"versionType": "custom"
},
{
"status": "affected",
"version": "9.0",
"lessThan": "9.0.10",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*"
],
"vendor": "splunk",
"product": "splunk_cloud_platform",
"versions": [
{
"status": "affected",
"version": "9.1.2312",
"lessThan": "9.1.2312.109",
"versionType": "custom"
},
{
"status": "affected",
"version": "9.1.2308",
"lessThan": "9.1.2308.207",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-07-01T17:15:06.257",
"references": [
{
"url": "https://advisory.splunk.com/advisories/SVD-2024-0703",
"tags": [
"Vendor Advisory"
],
"source": "prodsec@splunk.com"
},
{
"url": "https://research.splunk.com/application/1cf58ae1-9177-40b8-a26c-8966040f11ae/",
"tags": [
"Tool Signature"
],
"source": "prodsec@splunk.com"
},
{
"url": "https://advisory.splunk.com/advisories/SVD-2024-0703",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://research.splunk.com/application/1cf58ae1-9177-40b8-a26c-8966040f11ae/",
"tags": [
"Tool Signature"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "prodsec@splunk.com",
"description": [
{
"lang": "en",
"value": "CWE-77"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-77"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an authenticated user could create an external lookup that calls a legacy internal function. The authenticated user could use this internal function to insert code into the Splunk platform installation directory. From there, the user could execute arbitrary code on the Splunk platform Instance."
},
{
"lang": "es",
"value": "En las versiones de Splunk Enterprise inferiores a 9.2.2, 9.1.5 y 9.0.10 y en las versiones de Splunk Cloud Platform inferiores a 9.1.2312.109 y 9.1.2308.207, un usuario autenticado podría crear una búsqueda externa que llame a una función interna heredada. El usuario autenticado podría utilizar esta función interna para insertar código en el directorio de instalación de la plataforma Splunk. Desde allí, el usuario podría ejecutar código arbitrario en la instancia de la plataforma Splunk."
}
],
"lastModified": "2026-06-17T07:37:32.583",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "09264EE5-FA8A-49C5-AB1F-AEAC16CDC591",
"versionEndExcluding": "9.0.10",
"versionStartIncluding": "9.0.0"
},
{
"criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "565039EE-74F6-451C-AFB3-F6C9F7AA0EEE",
"versionEndExcluding": "9.1.5",
"versionStartIncluding": "9.1.0"
},
{
"criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B1342052-4733-49BB-95F0-A89B07A3F2E3",
"versionEndExcluding": "9.2.2",
"versionStartIncluding": "9.2.0"
},
{
"criteria": "cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D220E842-2B15-416F-960B-397166883F9F",
"versionEndExcluding": "9.1.2308.207",
"versionStartIncluding": "9.1.2308"
},
{
"criteria": "cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F2E66C0D-BD3A-46CE-9578-068401F094C0",
"versionEndExcluding": "9.1.2312.109",
"versionStartIncluding": "9.1.2312"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "prodsec@splunk.com"
}