CVE-2022-43572: Indexing blockage via malformed data sent through S2S or HEC protocols in Splunk Enterprise
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, sending a malformed file through the Splunk-to-Splunk (S2S) or HTTP Event Collector (HEC) protocols to an indexer results in a blockage or denial-of-service preventing further indexing.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 8.2.9 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 8.1.12 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.0.2
Event History
Frequently Asked Questions
What is CVE-2022-43572?
CVE-2022-43572 is a vulnerability in Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2 that allows a denial-of-service attack by sending a malformed file through the Splunk-to-Splunk (S2S) or HTTP Event Collector (HEC) protocols.
How does CVE-2022-43572 affect Splunk Enterprise?
CVE-2022-43572 affects Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, causing a blockage or denial-of-service that prevents further indexing.
Which versions of Splunk Enterprise are affected by CVE-2022-43572?
CVE-2022-43572 affects Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2.
What is the severity of CVE-2022-43572?
CVE-2022-43572 has a severity level of 6.5 (high).
How can I fix CVE-2022-43572?
To fix CVE-2022-43572, upgrade Splunk Enterprise to version 8.2.9, 8.1.12, or 9.0.2.