{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-02T04:54:15.855","vulnerabilities":[{"cve":{"id":"CVE-2025-20231","sourceIdentifier":"psirt@cisco.com","published":"2025-03-26T22:15:15.083","lastModified":"2026-06-17T08:41:08.520","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the “admin“ or “power“ Splunk roles could run a search using the permissions of a higher-privileged user that could lead to disclosure of sensitive information.<br><br>The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The authenticated low-privileged user should not be able to exploit the vulnerability at will."},{"lang":"es","value":"En las versiones de Splunk Enterprise anteriores a 9.4.1, 9.3.3, 9.2.5 y 9.1.8, y en las versiones anteriores a 3.8.38 y 3.7.23 de la aplicación Splunk Secure Gateway en Splunk Cloud Platform, un usuario con pocos privilegios que no tenga los roles de \"admin\" o \"power\" de Splunk podría realizar una búsqueda utilizando los permisos de un usuario con más privilegios, lo que podría dar lugar a la divulgación de información confidencial.<br><br>La vulnerabilidad requiere que el atacante suplante a la víctima, engañándola para que inicie una solicitud en su navegador. El usuario autenticado con pocos privilegios no debería poder explotar la vulnerabilidad a voluntad."}],"affected":[{"source":"psirt@cisco.com","affectedData":[{"vendor":"Splunk","product":"Splunk Enterprise","versions":[{"version":"9.4","lessThan":"9.4.1","versionType":"custom","status":"affected"},{"version":"9.3","lessThan":"9.3.3","versionType":"custom","status":"affected"},{"version":"9.2","lessThan":"9.2.5","versionType":"custom","status":"affected"},{"version":"9.1","lessThan":"9.1.8","versionType":"custom","status":"affected"}]},{"vendor":"Splunk","product":"Splunk Secure Gateway","versions":[{"version":"3.8","lessThan":"3.8.38","versionType":"custom","status":"affected"},{"version":"3.7","lessThan":"3.7.23","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@cisco.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N","baseScore":5.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-28T03:55:51.545096Z","id":"CVE-2025-20231","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@cisco.com","type":"Secondary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.1.0","versionEndExcluding":"9.1.8","matchCriteriaId":"49EE75F0-2AD6-4712-9E2A-C000A44E5605"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.2.0","versionEndExcluding":"9.2.5","matchCriteriaId":"5B7E20B1-E38E-4F5E-9F89-41FD4C231742"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"9.3.0","versionEndExcluding":"9.3.3","matchCriteriaId":"E66E66BA-AFC2-4E0A-B233-9E2C7D985AF0"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk:9.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"AD39F156-52DB-4F43-8528-37500E3AEB89"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk_secure_gateway:*:*:*:*:*:*:*:*","versionStartIncluding":"3.7.0","versionEndExcluding":"3.7.23","matchCriteriaId":"3B85AEDE-7363-42D5-8F3C-1865BB39166C"},{"vulnerable":true,"criteria":"cpe:2.3:a:splunk:splunk_secure_gateway:*:*:*:*:*:*:*:*","versionStartIncluding":"3.8.0","versionEndExcluding":"3.8.38","matchCriteriaId":"6DD62957-0C8B-49FC-BC63-2E0CDC041021"}]}]}],"references":[{"url":"https://advisory.splunk.com/advisories/SVD-2025-0302","source":"psirt@cisco.com","tags":["Vendor Advisory"]}]}}]}