CVE-2023-24495: SSRF
Published Jan 25, 2023
·Updated
A Server Side Request Forgery (SSRF) vulnerability exists in Tenable.sc due to improper validation of session & user-accessible input data. A privileged, authenticated remote attacker could interact with external and internal services covertly.
Affected Software
1 affected component
Tenable Tenable.Sc<=5.23.1
Remediation
Patch Available
Event History
Jan 25, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2023-24495.
2
What is the severity of CVE-2023-24495?
The severity of CVE-2023-24495 is medium (6.5).
3
What is the affected software for CVE-2023-24495?
The affected software for CVE-2023-24495 is Tenable.sc version 5.23.1.
4
What is the description of CVE-2023-24495?
CVE-2023-24495 is a Server Side Request Forgery (SSRF) vulnerability in Tenable.sc that allows privileged, authenticated remote attackers to interact with external and internal services covertly.
5
Is there a solution for CVE-2023-24495?
Yes, it is recommended to upgrade Tenable.sc to a version that includes a fix for CVE-2023-24495.