CVE-2024-1367

A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead to the execution of arbitrary code on the Security Center host.

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:tenable:security_center:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:50

Type Values Removed Values Added
References () https://www.tenable.com/security/tns-2024-02 - Vendor Advisory () https://www.tenable.com/security/tns-2024-02 - Vendor Advisory

19 Nov 2024, 16:06

Type Values Removed Values Added
CPE cpe:2.3:a:tenable:security_center:*:*:*:*:*:*:*:*
References () https://www.tenable.com/security/tns-2024-02 - () https://www.tenable.com/security/tns-2024-02 - Vendor Advisory
First Time Tenable
Tenable security Center

Information

Published : 2024-02-14 22:15

Updated : 2024-11-21 08:50


NVD link : CVE-2024-1367

Mitre link : CVE-2024-1367

CVE.ORG link : CVE-2024-1367


JSON object : View

Products Affected
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')