Splunk Enterprise 6.x < 6.0.1 Malformed Packet DoS

This script is Copyright (C) 2014-2015 Tenable Network Security, Inc.

Synopsis :

The remote web server contains an application that may be affected by
a denial of service vulnerability.

Description :

According to its version number, the Splunk Enterprise hosted on the
remote web server may be affected by a denial of service vulnerability
that is triggered by malformed network input, resulting in the Splunk
server becoming unavailable.

Note that this only affects Splunk Enterprise 6.0 components
configured as data 'receivers' on the listening or receiving port(s),
and it impacts Splunk Enterprise instances configured as indexers as
well as any forwarders configured as intermediate forwarders.

Note that Nessus has not tested for this issue but has instead relied
only on the application's self-reported version number.

See also :


Solution :

Upgrade to Splunk Enterprise 6.0.1 or later.

Risk factor :

High / CVSS Base Score : 7.8
CVSS Temporal Score : 6.8
Public Exploit Available : false

Family: Denial of Service

Nessus Plugin ID: 71784 ()

Bugtraq ID: 64419

CVE ID: CVE-2013-7337