CVE-2022-0130: High severity tenable.sc vulnerability
Published Jan 14, 2022
·Updated
Tenable.sc versions 5.14.0 through 5.19.1 were found to contain a remote code execution vulnerability which could allow a remote, unauthenticated attacker to execute code under special circumstances. An attacker would first have to stage a specific file type in the web server root of the Tenable.sc host prior to remote exploitation.
Affected Software
1 affected component
Tenable Tenable.Sc>=5.14.0<=5.19.1
Event History
Jan 14, 2022
CVE Published
via MITRE·07:11 PM
Data Sourced
via MITRE·07:11 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-0130?
CVE-2022-0130 is a remote code execution vulnerability in Tenable.sc versions 5.14.0 through 5.19.1.
2
How severe is CVE-2022-0130?
CVE-2022-0130 has a severity score of 8.1 (high).
3
What software versions are affected by CVE-2022-0130?
Tenable.sc versions 5.14.0 through 5.19.1 are affected by CVE-2022-0130.
4
How can an attacker exploit CVE-2022-0130?
An attacker can exploit CVE-2022-0130 by staging a specific file type in the web server root of the Tenable.sc application.
5
Is authentication required to exploit CVE-2022-0130?
No, CVE-2022-0130 can be exploited by an unauthenticated attacker.