Splunk removed two security analytics tied to CVE-2022-32151 after stating the underlying issues were patched in current releases. The retired detections had been designed to flag Splunk forwarder connections where ssl=false and to identify weak TLS certificate-validation settings in Python httplib and urllib components across search heads and peers. Splunk warned that these conditions could expose sensitive data, allow interception or manipulation of traffic, and in some cases enable attackers to download or publish forwarder bundles, creating a path to arbitrary code execution.
The risks align with the broader ATT&CK technique T1001.003: Protocol or Service Impersonation, which covers malware and intrusion sets that disguise command-and-control traffic as legitimate services or protocols such as TLS and HTTP. MITRE documents how adversaries use fake TLS handshakes, spoofed record headers, and benign-looking HTTP headers, cookies, URI parameters, and POST bodies to evade inspection. In Splunk environments, weak or absent encryption can make that kind of impersonation harder to distinguish from normal traffic, which is why the detections had focused on missing encryption and certificate-validation weaknesses before being deprecated in version 5.6.0.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Splunk Threat Research removed the detections "Splunk Digital Certificates Lack of Encryption" and "Splunk Protocol Impersonation Weak Encryption Configuration" from its content library, stating the associated CVEs had been patched in the latest Splunk release. Both notices say the detections were removed in content library version 5.6.0 and are no longer maintained.
Splunk published product security advisories SVD-2022-0601 and SVD-2022-0607 covering vulnerabilities including CVE-2022-32151, which later became the basis for related detections in Splunk Threat Research content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourceresearch.splunk.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.