Vulnerability Description
In universal forwarder versions before 9.0, management services are available remotely by default. When not required, it introduces a potential exposure, but it is not a vulnerability. If exposed, we recommend each customer assess the potential severity specific to your environment. In 9.0, the universal forwarder now binds the management port to localhost preventing remote logins by default. If management services are not required in versions before 9.0, set disableDefaultPort = true in server.conf OR allowRemoteLogin = never in server.conf OR mgmtHostPort = localhost in web.conf. See Configure universal forwarder management security (https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnameValidation#Configure_universal_forwarder_management_security) for more information on disabling the remote management services.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Splunk | Splunk | < 9.0 |
| Splunk | Splunk Cloud Platform | < 8.2.2106 |
Related Weaknesses (CWE)
References
- https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnamMitigationVendor Advisory
- https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/UpdatesRelease NotesVendor Advisory
- https://www.splunk.com/en_us/product-security/announcements/svd-2022-0605.htmlVendor Advisory
- https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/EnableTLSCertHostnamMitigationVendor Advisory
- https://docs.splunk.com/Documentation/Splunk/9.0.0/Security/UpdatesRelease NotesVendor Advisory
- https://www.splunk.com/en_us/product-security/announcements/svd-2022-0605.htmlVendor Advisory
FAQ
What is CVE-2022-32155?
CVE-2022-32155 is a vulnerability with a CVSS score of 7.5 (HIGH). In universal forwarder versions before 9.0, management services are available remotely by default. When not required, it introduces a potential exposure, but it is not a vulnerability. If exposed, we ...
How severe is CVE-2022-32155?
CVE-2022-32155 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-32155?
Check the references section above for vendor advisories and patch information. Affected products include: Splunk Splunk, Splunk Splunk Cloud Platform.