CVE-2024-1683
HIGHTenable Identity Exposure < 3.59.4 - OS Command Injection
Title source: ruleDescription
A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for overriding of the configuration and running of new Secure Relay services.
Scores
CVSS v3
7.3
EPSS
0.0003
EPSS Percentile
7.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L
Classification
CWE
CWE-78
Status
published
Affected Products (1)
tenable/identity_exposure
< 3.59.4
Timeline
Published
Feb 23, 2024
Tracked Since
Feb 18, 2026