CVE-2022-32156: Splunk Certificate Validation Flaw (CVSS 8.1)

CVE-2022-32156 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while connecting to a remote Splunk platform instance by default. After updating to version 9.0, see Configure TLS host name validation for the Splunk CLI here to enable the remediation. EPSS estimates a 0.74% chance of exploitation in the next 30 days.

Description

In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while connecting to a remote Splunk platform instance by default. This vulnerability does not affect the Splunk Cloud Platform. The issue requires conditions beyond the control of a potential bad actor, such as a machine-in-the-middle attack. Hence, Splunk rates the complexity of the attack as High.

Metrics

Weakness Enumeration

Affected Software

Vendor Product Versions
Splunk Splunk < 9.0
Splunk Universal Forwarder < 9.0

References

Timeline

Frequently Asked Questions

What is CVE-2022-32156?

In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while connecting to a remote Splunk platform instance by default.

How severe is CVE-2022-32156?

CVE-2022-32156 has a CVSS score of 8.1/10 (HIGH severity). The EPSS model estimates a 0.74% probability of exploitation in the next 30 days.

How do I fix CVE-2022-32156?

Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-32156?

Run a free Strix scan to check your systems for this vulnerability. Scan your code now

Source: NVD / NIST