PT-2022-12982 · Tenable · Tenable.Sc
Published
2022-01-14
·
Updated
2023-08-08
·
CVE-2022-0130
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tenable.sc versions 5.14.0 through 5.19.1
Description
A remote code execution issue was discovered, allowing a remote, unauthenticated attacker to execute code under special circumstances. The attacker must first stage a specific file type in the web server root of the Tenable.sc host prior to remote exploitation.
Recommendations
For Tenable.sc versions 5.14.0 through 5.19.1, update to a version that contains a fix for this issue to prevent remote code execution. As a temporary workaround, consider restricting access to the web server root to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tenable.Sc