First published: Fri Jan 14 2022(Updated: )
Tenable.sc versions 5.14.0 through 5.19.1 were found to contain a remote code execution vulnerability which could allow a remote, unauthenticated attacker to execute code under special circumstances. An attacker would first have to stage a specific file type in the web server root of the Tenable.sc host prior to remote exploitation.
Credit: vulnreport@tenable.com vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tenable Tenable.sc | >=5.14.0<=5.19.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0130 is a remote code execution vulnerability in Tenable.sc versions 5.14.0 through 5.19.1.
CVE-2022-0130 has a severity score of 8.1 (high).
Tenable.sc versions 5.14.0 through 5.19.1 are affected by CVE-2022-0130.
An attacker can exploit CVE-2022-0130 by staging a specific file type in the web server root of the Tenable.sc application.
No, CVE-2022-0130 can be exploited by an unauthenticated attacker.