{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-22T21:15:27.267","vulnerabilities":[{"cve":{"id":"CVE-2023-40596","sourceIdentifier":"prodsec@splunk.com","published":"2023-08-30T17:15:10.103","lastModified":"2026-06-17T06:18:38.267","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1, a dynamic link library (DLL) that ships with Splunk Enterprise references an insecure path for the OPENSSLDIR build definition. An attacker can abuse this reference and subsequently install malicious code to achieve privilege escalation on the Windows machine."},{"lang":"es","value":"En versiones de Splunk Enterprise anteriores a la 8.2.12, 9.0.6 y 9.1.1, una biblioteca de enlace dinámico (DLL) que se distribuye con Splunk Enterprise hace referencia a una ruta insegura para la definición de compilación OPENSSLDIR. Un atacante puede abusar de esta referencia y posteriormente instalar código malicioso para lograr la escalada de privilegios en la máquina Windows."}],"affected":[{"source":"prodsec@splunk.com","affectedData":[{"vendor":"Splunk","product":"Splunk Enterprise","versions":[{"version":"8.2","lessThan":"8.2.12","versionType":"custom","status":"affected"},{"version":"9.0","lessThan":"9.0.6","versionType":"custom","status":"affected"},{"version":"9.1","lessThan":"9.1.1","versionType":"custom","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"splunk","product":"splunk","defaultStatus":"unknown","cpes":["cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*"],"versions":[{"version":"8.2","lessThan":"8.2.12","versionType":"semver","status":"affected"},{"version":"9.0","lessThan":"9.0.6","versionType":"semver","status":"affected"},{"version":"9.1","lessThan":"9.1.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"prodsec@splunk.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.0,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.0,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.0,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-05-20T19:34:18.026500Z","id":"CVE-2023-40596","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"prodsec@splunk.com","type":"Secondary","description":[{"lang":"en","value":"CWE-665"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-427"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.2.0","versionEndExcluding":"8.2.12","matchCriteriaId":"21F6F824-393F-424F-85DF-CD3FCB40452F"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.0.0","versionEndExcluding":"9.0.6","matchCriteriaId":"74A23E71-6A34-48A5-8087-B626BED870E0"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:9.1.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"A4F2BC82-AD4C-4D80-8200-C2371E7C04F1"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://advisory.splunk.com/advisories/SVD-2023-0805","source":"prodsec@splunk.com","tags":["Vendor Advisory"]},{"url":"https://advisory.splunk.com/advisories/SVD-2023-0805","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}