Impact
The CVE identifies a weakness in Splunk Enterprise characterized by improper control of a resource through its lifetime (CWE‑664). The description states that internal resource handling may be deficient, which can give an attacker the ability to influence the allocation, usage, or deallocation of resources. The impact of such a flaw is not explicitly stated in the CNA notes, but it is inferred from the nature of the weakness that it could lead to resource exhaustion, service instability, or denial of service.
Affected Systems
Affected systems are Splunk Enterprise deployments that run the vulnerable releases listed in the advisory – versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The fix is available in those releases and in any later versions of Splunk Enterprise.
Risk and Exploitability
No EPSS score is provided, and the vulnerability is not listed in the CISA KEV catalog. The CNA does not supply a CVSS score, so a precise severity assessment cannot be calculated. It is inferred that exploitation of this resource‑management flaw could be achieved through legitimate user actions or by internal privileged users, potentially resulting in denial of service or other adverse effects. The lack of public exploitation evidence suggests the risk is lower than for known exploits, yet the potential impact on availability warrants prompt remediation.
OpenCVE Enrichment