CVE-2023-24493: Input Validation
A formula injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated attacker could leverage the reporting system to export reports containing formulas, which would then require a victim to approve and execute on a host.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-24493?
CVE-2023-24493 refers to a formula injection vulnerability in Tenable.sc, allowing an authenticated attacker to export reports containing malicious formulas.
How does CVE-2023-24493 affect Tenable.sc?
CVE-2023-24493 affects Tenable.sc by allowing an authenticated attacker to exploit the reporting system and export reports with malicious formulas.
What is the severity of CVE-2023-24493?
CVE-2023-24493 has a severity rating of 5.7 (medium).
How can an attacker exploit CVE-2023-24493?
An attacker can exploit CVE-2023-24493 by leveraging the reporting system in Tenable.sc to export reports containing malicious formulas.
How can I protect my Tenable.sc instance from CVE-2023-24493?
To protect your Tenable.sc instance from CVE-2023-24493, ensure you have the latest version installed with the necessary security patches and updates.