# CVE-2023-3997

## Summary

- **CVE ID:** CVE-2023-3997
- **Severity:** HIGH
- **CVSS Score:** 8.6 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
- **CWE:** CWE-117
- **Published:** Jul 31, 2023
- **Last Modified:** Mar 13, 2026

## Description

Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s terminal. A third party can send Splunk SOAR a maliciously crafted web request containing special ANSI characters to cause log file poisoning. When a terminal user attempts to view the poisoned logs, this can tamper with the terminal and cause possible malicious code execution from the terminal user’s action.

## Affected Products

- Splunk — Splunk SOAR (On-premises) (-)
- Splunk — Splunk SOAR (Cloud) (-)

## References

- [CNA](https://advisory.splunk.com/advisories/SVD-2023-0702)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.08%
- **EPSS Percentile:** 23.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._