header-logo
Suggest Exploit
vendor:
Splunk Enterprise
by:
Matteo Malvica
7.5
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Splunk Enterprise
Affected Version From: 7.2.4
Affected Version To: 7.2.4
Patch Exists: No
Related CWE: N/A
CPE: a:splunk:splunk_enterprise
Metasploit: N/A
Other Scripts: N/A
Platforms Tested: Kali 4.18.0-kali2-amd64
2019

Splunk Enterprise 7.2.4 Custom App RCE (persistent backdoor – custom binary payload)

This exploit allows an attacker to upload a malicious app to Splunk Enterprise 7.2.4, which can be used to execute arbitrary code on the target system.

Mitigation:

Ensure that all Splunk Enterprise versions are up to date and that all users have strong passwords.
Source

Exploit-DB raw data: