PT-2023-14178 · Tenable · Tenable

Ayman Abdul Kareem

·

Published

2023-03-15

·

Updated

2025-02-27

·

CVE-2022-4313

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tenable products (affected versions not specified)
Description A vulnerability was reported where an authenticated user with Scan Policy Configuration roles in Tenable products could manipulate audit policy variables by modifying the scan variables to execute arbitrary commands on credentialed scan targets.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2022-4313

Affected Products

Tenable