7.5
CWE
20 125
Advisory Published
Updated

CVE-2021-3422: Indexer denial-of-service via malformed S2S request

First published: Fri Mar 25 2022(Updated: )

The lack of validation of a key-value field in the Splunk-to-Splunk protocol results in a denial-of-service in Splunk Enterprise instances configured to index Universal Forwarder traffic. The vulnerability impacts Splunk Enterprise versions before 7.3.9, 8.0 versions before 8.0.9, and 8.1 versions before 8.1.3. It does not impact Universal Forwarders. When Splunk forwarding is secured using TLS or a Token, the attack requires compromising the certificate or token, or both. Implementation of either or both reduces the severity to Medium.

Credit: prodsec@splunk.com

Affected SoftwareAffected VersionHow to fix
Splunk<7.3.9
Splunk>=8.0<8.0.9
Splunk>=8.1<8.1.3

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2021-3422?

    CVE-2021-3422 has a medium severity rating due to its potential to cause a denial-of-service in affected Splunk Enterprise instances.

  • How do I fix CVE-2021-3422?

    To fix CVE-2021-3422, upgrade your Splunk Enterprise instances to versions 7.3.9, 8.0.9, or 8.1.3 or later.

  • Which versions of Splunk Enterprise are affected by CVE-2021-3422?

    CVE-2021-3422 affects Splunk Enterprise versions prior to 7.3.9 and 8.0 versions before 8.0.9.

  • Is CVE-2021-3422 exploitable remotely?

    Yes, CVE-2021-3422 can be exploited remotely by sending specially crafted requests to the Splunk-to-Splunk protocol.

  • What impact does CVE-2021-3422 have on Splunk services?

    CVE-2021-3422 can lead to a denial-of-service condition, disrupting Splunk Enterprise operations when indexing Universal Forwarder traffic.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203