Impact
In earlier releases of the Cisco Secure Malware Analytics app for Splunk SOAR, the detonate file action exposes the sample_password parameter in cleartext. A user with permission to run actions can invoke this action and see the password displayed in the user interface, constituting a disclosure of sensitive credentials. The weakness is a failure to mask the parameter, identified as CWE-312.
Affected Systems
The flaw affects the Cisco Secure Malware Analytics app for Splunk SOAR versions earlier than 2.4.5. The mitigation requires the app to be upgraded to a fixed version, which itself requires Splunk SOAR 8.6.0 or newer.
Risk and Exploitability
The vulnerability carries a CVSS score of 4.3, indicating a low-to-medium severity. The EPSS score is not available, so the precise likelihood of exploitation is uncertain, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would need a role that can run actions; the disclosure is therefore limited to internal users with sufficient privileges.
OpenCVE Enrichment