Command Injection Vulnerability in Tenable Scanner
CVE-2022-4313
8.8HIGH
What is CVE-2022-4313?
A command injection vulnerability exists in various Tenable products, allowing authenticated users with specific roles to manipulate scan policy variables. This manipulation can lead to the execution of arbitrary commands on credentialed scan targets, potentially compromising the security of the scanned environment. It is crucial for users to review their access roles and enforce stricter controls to mitigate the risk associated with this vulnerability.
Affected Version(s)
Tenable.io, Tenable.sc and Nessus Plugin Feed Version 202212081951 and earlier
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved