A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead to the execution of arbitrary code on the Security Center host.
References
Link | Resource |
---|---|
https://www.tenable.com/security/tns-2024-02 | Vendor Advisory |
https://www.tenable.com/security/tns-2024-02 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2024-02-14 22:15
Updated : 2024-11-21 08:50
NVD link : CVE-2024-1367
Mitre link : CVE-2024-1367
CVE.ORG link : CVE-2024-1367
JSON object : View
Products Affected
tenable
- security_center
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')