CVE-2017-8051: OS Command Injection
Published Apr 21, 2017
·Updated
Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of the tnsappliancesessionuser parameter, a remote attacker can inject arbitrary commands.
Affected Software
11 affected components
Tenable Appliance=3.4.0
Tenable Appliance=3.5.0
Tenable Appliance=3.5.1
Tenable Appliance=3.10.0
Tenable Appliance=3.10.1
Tenable Appliance=4.0.0
Tenable Appliance=4.1.0
Tenable Appliance=4.2.0
Tenable Appliance=4.3.0
Tenable Appliance=4.3.1
Tenable Appliance=4.4.0
Event History
Apr 21, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-8051?
CVE-2017-8051 has a high severity due to its potential for remote code execution.
2
How do I fix CVE-2017-8051?
To fix CVE-2017-8051, upgrade to Tenable Appliance version 4.4.0 or later.
3
Is CVE-2017-8051 easy to exploit?
Yes, CVE-2017-8051 can be easily exploited due to improper validation in the simpleupload.py script.
4
What systems are affected by CVE-2017-8051?
CVE-2017-8051 affects Tenable Appliance versions 3.4.0 through 4.4.0.
5
What type of attack does CVE-2017-8051 enable?
CVE-2017-8051 enables remote attackers to inject arbitrary commands into the system.