Impact
The vulnerability is a Server-Side Request Forgery in the Talos intelligence enrichment REST API. A user with the get_talos_enrichment capability can send a specially crafted request that causes the Splunk instance to make an outbound call to an attacker-controlled server. The data received by the server may contain authentication tokens that can compromise all relevant data and system integrity within the Splunk environment. The flaw arises from accepting a destination host from request data without proper validation, a weakness identified as CWE‑918.
Affected Systems
Affected systems are deployments of the Cisco Talos Intelligence for Enterprise Security Cloud Splunk app or add-on whose version is below 1.0.3. This includes all Splunk Enterprise Security instances that have installed the Cisco Talos Intelligence for Enterprise Security Cloud app prior to the release of the 1.0.3 patch.
Risk and Exploitability
The CVSS score of 8.8 classifies this flaw as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack appears to be limited to authenticated users who possess the get_talos_enrichment role, meaning the threat surface depends on internal role assignment. Because the flaw allows an attacker to obtain privileged tokens, the risk of data breach or potential lateral movement is significant.
OpenCVE Enrichment