VYPR
Medium severity6.3NVD Advisory· Published Aug 30, 2023· Updated Jun 17, 2026

CVE-2023-40593

CVE-2023-40593

Description

In Splunk Enterprise versions lower than 9.0.6 and 8.2.12, a malicious actor can send a malformed security assertion markup language (SAML) request to the /saml/acs REST endpoint which can cause a denial of service through a crash or hang of the Splunk daemon.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
    Range: >=8.2.0,<8.2.12
  • cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*range: <=9.0.2305.100
    • (no CPE)range: -
  • Splunk/Splunk Enterprisellm-fuzzy2 versions
    <9.0.6, <8.2.12+ 1 more
    • (no CPE)range: <9.0.6, <8.2.12
    • (no CPE)range: 8.2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.