Impact
A flaw in the Nmap Scanner connector for Splunk SOAR allows a user who can edit, create, or run playbooks to execute network scans in Safe Mode playbooks that are incorrectly marked as read‑only. Because the scan network action accepts script parameters that can perform write operations, the attacker can run arbitrary commands on the target system. This results in unauthorized command execution, a violation of confidentiality, integrity, and availability. The weakness is classified as CWE‑732, Incorrect Permission Assignment.
Affected Systems
Splunk SOAR users with the Connector: Nmap Scanner installed in versions earlier than 3.0.15 are affected. Any playbook that includes the scan network action as read‑only in this version can be abused.
Risk and Exploitability
The CVSS score of 6.6 indicates a moderate severity. EPSS is not available and the vulnerability is not listed in CISA KEV. The likely attack vector requires an authenticated Splunk SOAR user with playbook creation or editing permissions, so the risk is confined to environments where such roles are assigned. The exploit would involve adding or modifying a Safe Mode playbook to invoke the scan network action with parameters that trigger executable scripts on the target. The impacts are limited to systems reachable by the Nmap scan and do not require external network access to the Splunk platform itself.
OpenCVE Enrichment