First published: Thu Jan 26 2023(Updated: )
A Server Side Request Forgery (SSRF) vulnerability exists in Tenable.sc due to improper validation of session & user-accessible input data. A privileged, authenticated remote attacker could interact with external and internal services covertly.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tenable Tenable.sc | <=5.23.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-24495.
The severity of CVE-2023-24495 is medium (6.5).
The affected software for CVE-2023-24495 is Tenable.sc version 5.23.1.
CVE-2023-24495 is a Server Side Request Forgery (SSRF) vulnerability in Tenable.sc that allows privileged, authenticated remote attackers to interact with external and internal services covertly.
Yes, it is recommended to upgrade Tenable.sc to a version that includes a fix for CVE-2023-24495.