Security

Does CVE-2021-3422 also affect HWFs and IFs?

KeithH
Path Finder

Hi All,

Does the recently announced security vulnerability CVE-2021-3422 also apply to HWFs and IF that might be receiving and/or cooking data?

Thanks

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Heavy and Intermediate forwarders are the same executable (binary) file as Splunk Enterprise and so are subject to the same vulnerabilities.

---
If this reply helps you, an upvote would be appreciated.

View solution in original post

KeithH
Path Finder

This site seems to have the best overview of the problem - still doesnt make it clear to me though if a HWF (that isnt indexing) might be affected:

https://claroty.com/2022/03/24/blog-research-splunk-patches-indexer-vulnerability-disclosed-by-team8...

Splunks announcement provides little detail:

https://www.splunk.com/en_us/product-security/announcements/svd-2022-0301.html

 

0 Karma

PickleRick
Ultra Champion

It still doesn't provide enough information to be 100% sure but it seems the code is linked to parsing the data on splunktcp input so it probably affects HFs too.

But as I said, not enough info to be fully sure.

richgalloway
SplunkTrust
SplunkTrust

Heavy and Intermediate forwarders are the same executable (binary) file as Splunk Enterprise and so are subject to the same vulnerabilities.

---
If this reply helps you, an upvote would be appreciated.

KeithH
Path Finder

Hi Rich,

That was my conern too but the description of the CVE says 

"Indexer denial-of-service via malformed S2S request"

Which makes it sound related to the indexer functions. 

Is an HWF or IF that is not indexing still at risk?

Ta, Keith

0 Karma

PickleRick
Ultra Champion

I can't see any details under the link you provided (and I can't find any info on the given CVE ID).

But S2S is a protocol used between different splunk instances (forwarder to forwarder, forwarder to indexer).

Unfortunately it's hard to say without more detailed knowledge of the CVE whether the vulnerability is connected with the code processing the data incoming from the network input (in which case it would most probably be applicable to any splunk component waiting for data on splunktcp:// input) or if it's in the data indexing part (in which case of course it would apply only to indexers as such).

Get Updates on the Splunk Community!

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...

Reminder! Splunk Love Promo: $25 Visa Gift Card for Your Honest SOAR Review With ...

We recently launched our first Splunk Love Special, and it's gone phenomenally well, so we're doing it again, ...