← back
CVE-2023-32706highCWE-611

Denial Of Service due to Untrusted XML Tag in XML Parser within SAML Authentication

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.7epss 0.6%
exploitation probability
0.6%top 53% of all CVEs
observed exploitation
nono source reports it
On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, an unauthenticated attacker can send specially-crafted messages to the XML parser within SAML authentication to cause a denial of service in the Splunk daemon.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H