CVE-2024-1367
Command Injection Vulnerability in Tenable Security Center
A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead to the execution of arbitrary code on the Security Center host.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
Tenable · Security CenterQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://www.tenable.com/security/tns-2024-02