« Volver al listado

CVE-2024-45736

Estado: AnalizadaMedia (6.5)—

In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2312.204, and 9.1.2312.111, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a search query with an improperly formatted "INGEST_EVAL" parameter as part of a [Field Transformation](https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Managefieldtransforms) which could crash the Splunk daemon (splunkd).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-45736",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-45736",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-10-15T16:36:03.459233Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "prodsec@splunk.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "prodsec@splunk.com",
      "affectedData": [
        {
          "vendor": "Splunk",
          "product": "Splunk Enterprise",
          "versions": [
            {
              "status": "affected",
              "version": "9.3",
              "lessThan": "9.3.1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.2",
              "lessThan": "9.2.3",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.1",
              "lessThan": "9.1.6",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Splunk",
          "product": "Splunk Cloud Platform",
          "versions": [
            {
              "status": "affected",
              "version": "9.2.2403",
              "lessThan": "9.2.2403.107",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.1.2312",
              "lessThan": "9.1.2312.204",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.1.2312",
              "lessThan": "9.1.2312.111",
              "versionType": "custom"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:splunk:splunk_enterprise:*:*:*:*:*:*:*:*"
          ],
          "vendor": "splunk",
          "product": "splunk_enterprise",
          "versions": [
            {
              "status": "affected",
              "version": "9.3",
              "lessThan": "9.3.1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.2",
              "lessThan": "9.2.3",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.1",
              "lessThan": "9.1.6",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*"
          ],
          "vendor": "splunk",
          "product": "splunk_cloud_platform",
          "versions": [
            {
              "status": "affected",
              "version": "9.2.2403",
              "lessThan": "9.2.2403.107",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.1.2312",
              "lessThan": "9.1.2312.204",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.1.2312",
              "lessThan": "9.1.2312.111",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-10-14T17:15:12.253",
  "references": [
    {
      "url": "https://advisory.splunk.com/advisories/SVD-2024-1006",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "prodsec@splunk.com"
    },
    {
      "url": "https://research.splunk.com/application/08978eca-caff-44c1-84dc-53f17def4e14/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "prodsec@splunk.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "prodsec@splunk.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2312.204, and 9.1.2312.111, a low-privileged user that does not hold the \"admin\" or \"power\" Splunk roles could craft a search query with an improperly formatted  \"INGEST_EVAL\" parameter as part of a [Field Transformation](https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Managefieldtransforms) which could crash the Splunk daemon (splunkd)."
    },
    {
      "lang": "es",
      "value": "En las versiones de Splunk Enterprise anteriores a 9.3.1, 9.2.3 y 9.1.6 y en las versiones de Splunk Cloud Platform anteriores a 9.2.2403.107, 9.1.2312.204 y 9.1.2312.111, un usuario con privilegios bajos que no tenga los roles de \"administrador\" o \"poder\" de Splunk podría crear una consulta de búsqueda con un parámetro \"INGEST_EVAL\" con formato incorrecto como parte de una [Transformación de campo](https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Managefieldtransforms) que podría bloquear el daemon de Splunk (splunkd)."
    }
  ],
  "lastModified": "2026-06-17T07:54:43.500",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FB935ACC-3899-47DE-B4C0-CB94CAC79AC2",
              "versionEndExcluding": "9.1.6",
              "versionStartIncluding": "9.1.0"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14D07F5E-504B-447B-988B-BF6ADA59F8D1",
              "versionEndExcluding": "9.2.3",
              "versionStartIncluding": "9.2.0"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk:9.3.0:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "11F038B4-1335-4F4E-9013-E6D6152DCD20"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "15F34E1D-7623-4A3F-A67E-01A11615DD27",
              "versionEndExcluding": "9.1.2312.111",
              "versionStartIncluding": "9.1.2312"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A5FE71F-0F59-4553-9480-AFA1CED9255E",
              "versionEndExcluding": "9.1.2312.204",
              "versionStartIncluding": "9.1.2312.200"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CCE7C5DF-BC89-4789-94DA-5F8D2D86C7DE",
              "versionEndExcluding": "9.2.2403.107",
              "versionStartIncluding": "9.2.2403.100"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "prodsec@splunk.com"
}