CVE-2024-12174: Low severity tenable.sc vulnerability
An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged attacker could intercept email messages sent from Security Center via a rogue SMTP server.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12174?
CVE-2024-12174 is classified as a high-severity vulnerability due to its potential to allow authenticated attackers to intercept sensitive email communications.
How do I fix CVE-2024-12174?
To fix CVE-2024-12174, update Tenable Security Center to the latest version where the improper certificate validation issue has been resolved.
What is the impact of CVE-2024-12174?
The impact of CVE-2024-12174 includes the risk of sensitive email interception if a privileged attacker successfully connects a rogue SMTP server.
Who is affected by CVE-2024-12174?
CVE-2024-12174 affects users of Tenable Security Center who have not updated their software to the version that addresses this vulnerability.
Is CVE-2024-12174 remotely exploitable?
CVE-2024-12174 is not remotely exploitable as it requires authenticated, privileged access to the Tenable Security Center.