Impact
The vulnerability in Splunk Enterprise is classified as a protection mechanism failure. Splunk identified multiple internally discovered flaws that could allow an attacker to bypass the system's safeguards, potentially enabling privilege escalation or unauthorized access to protected data or functionality, thereby compromising confidentiality and integrity.
Affected Systems
The affected product is Splunk Enterprise. Vulnerable versions are all releases older than Splunk Enterprise 10.4.3, 10.2.7, 10.0.10, or 9.4.15; any releases prior to those patched versions are at risk.
Risk and Exploitability
EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog, indicating no publicly disclosed exploit. The advisory does not provide an explicit attack vector; based on typical scenarios for protection mechanism failures, the likely attack vector could be remote through exposed interfaces, although this is inferred. The CVSS rating is not disclosed in the provided data, so the exact severity cannot be quantified. The weakness type (CWE-693) suggests a high potential for unauthorized access if exploited.
OpenCVE Enrichment