Advisory ID: SP-CAAAH76 CVE ID: CVE-2013-6771 Published: 2013-09-23 Last Update: 2014-03-10 Bug ID: SPL-70250 Description: - Abuse of a test script mechanism to execute shell code Affected Products and Components: - SPL-70250: Splunk 5.0.4 and all older versions Mitigation and Upgrades: - Upgrade to the latest release and apply Hardening Standards from the Securing Splunk documentation. Vulnerability Description and Rating: - CVSS Severity (version 2.0): - CVSS Base Score: 8.5 - CVSS Impact Subscore: 10 - CVSS Exploitability Subscore: 6.8 - Overall CVSS Score: 7 Document History: - 2013-Sep-23: Rev 1. Initial Release - 2014-Mar-10: Rev 2. Included CyberCrown Ltd working with HP's Zero Day Initiative