4.9
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Description
In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a user who holds a role that contains the high-privilege capability `change_authentication`, could send multiple LDAP bind requests to a specific internal endpoint, resulting in high server CPU usage, which could potentially lead to a denial of service (DoS) until the Splunk Enterprise instance is restarted. See https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.0/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities and https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.0/use-ldap-as-an-authentication-scheme/configure-ldap-with-splunk-web#cfe47e31_007f_460d_8b3d_8505ffc3f0dd__Configure_LDAP_with_Splunk_Web for more information.
Basic Information
ID
CVE-2025-20370
Source
cisco
Published
Oct 1, 2025 at 16:07
Affected Product
Vendor
Splunk
Product
Splunk Enterprise
Version
10.0
Affected Versions
Splunk Splunk Enterprise 10.0
Splunk Splunk Enterprise 9.4
Splunk Splunk Enterprise 9.3
Splunk Splunk Enterprise 9.2
Splunk Splunk Enterprise Cloud 9.3.2411
Splunk Splunk Enterprise Cloud 9.3.2408
Splunk Splunk Enterprise Cloud 9.2.2406
Splunk Splunk Enterprise 9.4
Splunk Splunk Enterprise 9.3
Splunk Splunk Enterprise 9.2
Splunk Splunk Enterprise Cloud 9.3.2411
Splunk Splunk Enterprise Cloud 9.3.2408
Splunk Splunk Enterprise Cloud 9.2.2406