CVE-2023-32713
Local Privilege Escalation via the ‘streamfwd’ program in Splunk App for Stream
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.8EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
01 Jun 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In Splunk App for Stream versions below 8.1.1, a low-privileged user could use a vulnerability in the streamfwd process within the Splunk App for Stream to escalate their privileges on the machine that runs the Splunk Enterprise instance, up to and including the root user.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
Splunk · Splunk App for StreamWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →