Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-0524

Опубликовано: 01 фев. 2023
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

As part of our Security Development Lifecycle, a potential privilege escalation issue was identified internally. This could allow a malicious actor with sufficient permissions to modify environment variables and abuse an impacted plugin in order to escalate privileges. We have resolved the issue and also made several defense-in-depth fixes alongside. While the probability of successful exploitation is low, Tenable is committed to securing our customers’ environments and our products. The updates have been distributed via the Tenable plugin feed in feed serial numbers equal to or greater than #202212212055.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:tenable:nessus:-:*:*:*:*:*:*:*
cpe:2.3:a:tenable:tenable.io:-:*:*:*:*:*:*:*
cpe:2.3:a:tenable:tenable.sc:-:*:*:*:*:*:*:*

EPSS

Процентиль: 40%
0.00184
Низкий

8.8 High

CVSS3

Дефекты

NVD-CWE-noinfo
CWE-269

Связанные уязвимости

CVSS3: 8.8
github
больше 2 лет назад

As part of our Security Development Lifecycle, a potential privilege escalation issue was identified internally. This could allow a malicious actor with sufficient permissions to modify environment variables and abuse an impacted plugin in order to escalate privileges. We have resolved the issue and also made several defense-in-depth fixes alongside. While the probability of successful exploitation is low, Tenable is committed to securing our customers’ environments and our products. The updates have been distributed via the Tenable plugin feed in feed serial numbers equal to or greater than #202212212055.

CVSS3: 9.1
fstec
около 3 лет назад

Уязвимость систем безопасности и оценки уязвимостей Nessus, tenable.io, tenable.sc, связанная с ошибками в коде, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 40%
0.00184
Низкий

8.8 High

CVSS3

Дефекты

NVD-CWE-noinfo
CWE-269