« Volver al listado

CVE-2025-20324

Estado: AnalizadaMedia (5.4)—

In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.7, and 9.1.10 and Splunk Cloud Platform versions below 9.3.2411.104, 9.3.2408.113, and 9.2.2406.119, a low-privileged user that does not hold the "admin" or "power" Splunk roles could create or overwrite [system source type](https://help.splunk.com/en/splunk-enterprise/get-started/get-data-in/9.2/configure-source-types/create-source-types) configurations by sending a specially-crafted payload to the `/servicesNS/nobody/search/admin/sourcetypes/` REST endpoint on the Splunk management port.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-20324",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-20324",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-07-08T13:36:47.709223Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@cisco.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@cisco.com",
      "affectedData": [
        {
          "vendor": "Splunk",
          "product": "Splunk Enterprise",
          "versions": [
            {
              "status": "affected",
              "version": "9.4",
              "lessThan": "9.4.2",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.3",
              "lessThan": "9.3.5",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.2",
              "lessThan": "9.2.7",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.1",
              "lessThan": "9.1.10",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Splunk",
          "product": "Splunk Enterprise Cloud",
          "versions": [
            {
              "status": "affected",
              "version": "9.3.2411",
              "lessThan": "9.3.2411.104",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.3.2408",
              "lessThan": "9.3.2408.113",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "9.2.2406",
              "lessThan": "9.2.2406.119",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-07-07T18:15:26.633",
  "references": [
    {
      "url": "https://advisory.splunk.com/advisories/SVD-2025-0707",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@cisco.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@cisco.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.7, and 9.1.10 and Splunk Cloud Platform versions below 9.3.2411.104, 9.3.2408.113, and 9.2.2406.119, a low-privileged user that does not hold the \"admin\" or \"power\" Splunk roles could create or overwrite [system source type](https://help.splunk.com/en/splunk-enterprise/get-started/get-data-in/9.2/configure-source-types/create-source-types) configurations by sending a specially-crafted payload to the `/servicesNS/nobody/search/admin/sourcetypes/` REST endpoint on the Splunk management port."
    },
    {
      "lang": "es",
      "value": "En las versiones de Splunk Enterprise anteriores a 9.4.2, 9.3.5, 9.2.7 y 9.1.10 y Splunk Cloud Platform anteriores a 9.3.2411.104, 9.3.2408.113 y 9.2.2406.119, un usuario con privilegios bajos que no tenga los roles de \"administrador\" o \"poder\" de Splunk podría crear o sobrescribir configuraciones de [tipo de origen del sistema](https://help.splunk.com/en/splunk-enterprise/get-started/get-data-in/9.2/configure-source-types/create-source-types) enviando un payload especialmente manipulada al endpoint REST `/servicesNS/nobody/search/admin/sourcetypes/` en el puerto de administración de Splunk."
    }
  ],
  "lastModified": "2026-06-17T08:41:27.853",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F363265C-BE8B-4D9E-BCD7-52D75D4454BA",
              "versionEndExcluding": "9.1.10",
              "versionStartIncluding": "9.1.0"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "16D7B94B-6E57-4462-BDB1-884E3268967D",
              "versionEndExcluding": "9.2.7",
              "versionStartIncluding": "9.2.0"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2AE238E0-742D-4595-8F72-C2D7256718EA",
              "versionEndExcluding": "9.3.5",
              "versionStartIncluding": "9.3.0"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "18674A90-13F1-4051-BD16-F815831CBE91",
              "versionEndExcluding": "9.4.2",
              "versionStartIncluding": "9.4.0"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6591B175-F288-4EE6-809A-A2E9B271EDC1",
              "versionEndExcluding": "9.2.2406.119",
              "versionStartIncluding": "9.2.2406"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F337F0F2-005E-4181-98D3-28DAB3C36BE6",
              "versionEndExcluding": "9.3.2408.113",
              "versionStartIncluding": "9.3.2408"
            },
            {
              "criteria": "cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0450CB69-409C-4289-B210-CEB463C77C13",
              "versionEndExcluding": "9.3.2411.104",
              "versionStartIncluding": "9.3.2411"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@cisco.com"
}