CVE-2024-1367

HIGH

Tenable Security Center < 6.3.0 - Authenticated OS Command Injection via Logging Parameters

Title source: llm
STIX 2.1

Description

A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead to the execution of arbitrary code on the Security Center host.

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0510
EPSS Percentile 89.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
tenable/security_center < 6.3.0
Published Feb 14, 2024
Tracked Since Feb 18, 2026