Impact
A misconfigured permission setting in the FireAMP connector allows a user with the ability to edit or run playbooks to execute the add listitem action in Safe Mode, even though the action is labeled read‑only. This results in unauthorized modifications to file lists, effectively changing security‑critical configuration data. The weakness is a classic permission assignment error identified as CWE‑732.
Affected Systems
The issue affects Splunk FireAMP connectors in Splunk SOAR versions earlier than 2.1.15. Any deployment of the FireAMP app that has not been updated to the fixed release is vulnerable.
Risk and Exploitability
The CVSS score of 2.7 indicates a low severity threat, and the EPSS score is not available, implying a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker would need a role that permits editing or executing playbooks, meaning the attack vector is internal and restricted to privileged users. Because the action is run while marked read‑only, exploitation requires only that the user can trigger the playbook, so the risk is largely tied to misconfigured role assignments rather than an external attack surface.
OpenCVE Enrichment