CVE-2018-11409
CVE-2018-11409
Vexday Risk Score
60Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS —EPSS 98.2%KEV nãoPoC públicaNuclei simMetasploit simPatch —
Lifecycle
08 Jun 2018Metasploit module available
08 Jun 2018Public PoC
08 Jun 2018Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated by discovering a license key.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/44865/unverifiedexploitdbwww.exploit-db.com/exploits/44865unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →