Impact
The advisory notes multiple internally identified vulnerabilities in Splunk Enterprise that stem from improper adherence to coding standards – a weakness catalogued as CWE‑710. The released security notes do not detail the exact defect or the resulting security consequences, leaving the effect on confidentiality, integrity, or availability unspecified. Because the description cites only a broad coding‑standard violation, the precise impact cannot be determined from the available information.
Affected Systems
Splunk Enterprise users running versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15 are affected. Earlier releases that have not incorporated the identified fixes remain vulnerable, and any deployment that has not been upgraded to at least the specified patch level remains at risk.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in CISA KEV, indicating no public exploitation evidence currently. The lack of an assigned CVSS score also prevents a quantitative severity assessment. Although the advisory does not describe an exposed external interface, it is inferred that the exploit might require an internal code‑execution path or additional weaknesses to be exploitable. Given the absence of public exploits and the undefined impact, the overall risk may be considered low to uncertain until further details emerge.
OpenCVE Enrichment