CVE-2025-20319 Information

Description

In Splunk Enterprise versions below 9.4.3 9.3.5 9.2.7 and 9.1.10 a user who holds a role that contains the high-privilege capability edit_scripted and list_inputs capability could perform a remote command execution due to improper user input sanitization on the scripted input files.

See Define roles on the Splunk platform with capabilities and Setting up a scripted input for more information.

CVSS Vector

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Reference

https://advisory.splunk.com/advisories/SVD-2025-0702

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction Required

HIGH

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

6.8

CNNVD-202507-750 (Published: 2025-07-07)

Share on: