CVE-2023-40594: Denial of Service (DoS) via the ‘printf’ Search Function
In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can use the printf SPL function to perform a denial of service (DoS) against the Splunk Enterprise instance.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-40594?
CVE-2023-40594 is a vulnerability in Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1 that allows an attacker to perform a denial of service (DoS) using the `printf` SPL function.
How does CVE-2023-40594 affect Splunk Enterprise?
CVE-2023-40594 affects Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1.
What is the severity of CVE-2023-40594?
The severity of CVE-2023-40594 is high, with a severity value of 7.5.
How can an attacker exploit CVE-2023-40594?
An attacker can exploit CVE-2023-40594 by using the `printf` SPL function to perform a denial of service (DoS) against the Splunk Enterprise instance.
How can I protect my Splunk Enterprise instance from CVE-2023-40594?
To protect your Splunk Enterprise instance from CVE-2023-40594, update to versions 8.2.12, 9.0.6, or 9.1.1 of Splunk Enterprise.