PoC Index

CVE-2024-36991

HIGH 7.5EPSS 13.0%

In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This vulnerability should only affect Splunk Enterprise on Windows.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
13.01% chance of exploitation in the next 30 days, 96th percentile
Nuclei
high
Published
2024-07-01
Updated
2025-02-28

Proof-of-concept exploits (13)

Nuclei templates (1)

References

Related