Impact
An unauthenticated user can download the OpenAPI specification exposed through Splunk Web static file paths in Cisco Talos Intelligence for Enterprise Security Cloud versions earlier than 1.0.3. The specification reveals all REST API endpoints and the authentication model, enabling an attacker to plan further attacks against the app. Because the file is served without authentication, the vulnerability allows information disclosure and could serve as a reconnaissance step.
Affected Systems
The affected product is Splunk’s Cisco Talos Intelligence for Enterprise Security Cloud app. Versions below 1.0.3 are vulnerable. Any deployment of the app on Splunk Web exposes the OpenAPI specification to unauthenticated users.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS data is available and the vulnerability is not listed in CISA KEV, suggesting low exploitation probability at present. The attack vector is inferred from the description to be over the network via Splunk Web, as the vulnerability arises when the OpenAPI spec is packaged as a static file served without authentication.
OpenCVE Enrichment