Command Injection Vulnerability in Tenable Scanner
CVE-2022-4313
8.8HIGH
What is CVE-2022-4313?
A command injection vulnerability exists in various Tenable products, allowing authenticated users with specific roles to manipulate scan policy variables. This manipulation can lead to the execution of arbitrary commands on credentialed scan targets, potentially compromising the security of the scanned environment. It is crucial for users to review their access roles and enforce stricter controls to mitigate the risk associated with this vulnerability.
Affected Version(s)
Tenable.io, Tenable.sc and Nessus Plugin Feed Version 202212081951 and earlier