CVE-2023-0476: Medium severity tenable.sc vulnerability
A LDAP injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated attacker could generate data in Active Directory using the application account through blind LDAP injection.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-0476?
CVE-2023-0476 is a LDAP injection vulnerability in Tenable.sc.
How does the LDAP injection vulnerability in CVE-2023-0476 affect Tenable.sc?
The LDAP injection vulnerability in CVE-2023-0476 allows an authenticated attacker to generate data in Active Directory using the application account through blind LDAP injection.
What is the severity of CVE-2023-0476?
CVE-2023-0476 has a severity rating of medium with a score of 6.5.
How can the LDAP injection vulnerability in CVE-2023-0476 be fixed?
To fix the LDAP injection vulnerability in CVE-2023-0476, proper validation of user-supplied input should be implemented before returning it to users.
Where can I find more information about CVE-2023-0476?
You can find more information about CVE-2023-0476 at the following link: https://www.tenable.com/security/tns-2023-03