« Volver al listado

CVE-2024-53246

Estado: AnalizadaAlta (7.5)—

In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.3.2408.101, 9.2.2406.106, 9.2.2403.111, and 9.1.2312.206, an SPL command can potentially disclose sensitive information. The vulnerability requires the exploitation of another vulnerability, such as a Risky Commands Bypass, for successful exploitation.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Aplicación Splunk expuesta en red (AV:N, PR:N, UI:N); el CWE-319 (transmisión de datos sensibles sin encriptación) y la descripción confirman lectura no autorizada de información sensible mediante comando SPL abusado.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-53246",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-53246",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-12-10T20:39:36.685783Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "prodsec@splunk.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.6
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "prodsec@splunk.com",
      "affectedData": [
        {
          "vendor": "Splunk",
          "product": "Splunk Enterprise",
          "versions": [
            {
              "status": "affected",
              "version": "9.3",
              "lessThan": "9.3.2",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.2",
              "lessThan": "9.2.4",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.1",
              "lessThan": "9.1.7",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Splunk",
          "product": "Splunk Cloud Platform",
          "versions": [
            {
              "status": "affected",
              "version": "9.3.2408",
              "lessThan": "9.3.2408.101",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.2.2406",
              "lessThan": "9.2.2406.106",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.2.2403",
              "lessThan": "9.2.2403.111",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.1.2312",
              "lessThan": "9.1.2312.206",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2024-12-10T18:15:41.553",
  "references": [
    {
      "url": "https://advisory.splunk.com/advisories/SVD-2024-1204",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "prodsec@splunk.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "prodsec@splunk.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-319"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-319"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.3.2408.101, 9.2.2406.106, 9.2.2403.111, and 9.1.2312.206, an SPL command can potentially disclose sensitive information. The vulnerability requires the exploitation of another vulnerability, such as a Risky Commands Bypass, for successful exploitation."
    },
    {
      "lang": "es",
      "value": "En las versiones de Splunk Enterprise anteriores a 9.3.2, 9.2.4 y 9.1.7 y en las versiones de Splunk Cloud Platform anteriores a 9.3.2408.101, 9.2.2406.106, 9.2.2403.111 y 9.1.2312.206, un comando SPL puede revelar información confidencial. La vulnerabilidad requiere la explotación de otra vulnerabilidad, como Risky Commands Bypass, para una explotación exitosa."
    }
  ],
  "lastModified": "2026-06-17T08:08:41.553",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6653C37D-03C0-47C1-BC9C-510EBB0CB4BE",
              "versionEndExcluding": "9.1.7",
              "versionStartIncluding": "9.1.0"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E31DE8DF-1AAD-4570-93E3-711C07FE1227",
              "versionEndExcluding": "9.2.4",
              "versionStartIncluding": "9.2.0"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A709D871-A35B-4CF2-A9D7-23CE29D0A8C6",
              "versionEndExcluding": "9.3.2",
              "versionStartIncluding": "9.3.0"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C0338CF9-1AC9-4F45-9A68-06172C6B36A1",
              "versionEndExcluding": "9.1.2312.206",
              "versionStartIncluding": "9.1.2312"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A95FCF8-8741-4577-8A0D-BDE7DCC1B720",
              "versionEndExcluding": "9.2.2403.111",
              "versionStartIncluding": "9.2.2403"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "62C1B5C7-2523-464D-9114-5C9F07AAEE9F",
              "versionEndExcluding": "9.2.2406.106",
              "versionStartIncluding": "9.2.2406"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9AF2CBAC-EF5D-4E0A-8B8D-900583D44876",
              "versionEndExcluding": "9.3.2408.101",
              "versionStartIncluding": "9.3.2408"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "prodsec@splunk.com"
}