8
CVE-2025-20298
- EPSS 0.06%
- Veröffentlicht 02.06.2025 17:14:03
- Zuletzt bearbeitet 04.08.2025 18:19:54
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory (by default, C:\Program Files\SplunkUniversalForwarder). This lets non-administrator users on the machine access the directory and all its contents.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Splunk ≫ Universal Forwarder Version >= 9.1.0 < 9.1.9
Splunk ≫ Universal Forwarder Version >= 9.2.0 < 9.2.6
Splunk ≫ Universal Forwarder Version >= 9.3.0 < 9.3.4
Splunk ≫ Universal Forwarder Version >= 9.4.0 < 9.4.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.06% | 0.189 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
psirt@cisco.com | 8 | 2.1 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
|
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.