Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s terminal. A third party can send Splunk SOAR a maliciously crafted web request containing special ANSI characters to cause log file poisoning. When a terminal user attempts to view the poisoned logs, this can tamper with the terminal and cause possible malicious code execution from the terminal user’s action.
CVE ID: CVE-2023-3997
CVSS Base Severity: HIGH
CVSS Base Score: 8.6
Vendor: Splunk
Product: Splunk SOAR (On-premises)
EPSS Score: 0.06% (probability of being exploited)
EPSS Percentile: 29.07% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)