Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-11508

Опубликовано: 02 нояб. 2017
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans. An attacker could exploit this vulnerability by entering a crafted SQL query into the password field of a diagnostic scan within SecurityCenter. Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:tenable:securitycenter:5.5.0:*:*:*:*:*:*:*
cpe:2.3:a:tenable:securitycenter:5.5.1:*:*:*:*:*:*:*
cpe:2.3:a:tenable:securitycenter:5.5.2:*:*:*:*:*:*:*

EPSS

Процентиль: 62%
0.00435
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans. An attacker could exploit this vulnerability by entering a crafted SQL query into the password field of a diagnostic scan within SecurityCenter. Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access.

EPSS

Процентиль: 62%
0.00435
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-89