CVE-2024-1367: Command Injection Vulnerability in Tenable Security Center
A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead to the execution of arbitrary code on the Security Center host.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tenable Security Centerto a version that resolves this vulnerability.Fixed in 6.3.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1367?
CVE-2024-1367 is classified as a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2024-1367?
To fix CVE-2024-1367, upgrade Tenable Security Center to version 6.3.0 or later.
Who is affected by CVE-2024-1367?
CVE-2024-1367 affects authenticated remote attackers with administrator privileges on Tenable Security Center versions prior to 6.3.0.
What types of attacks can exploit CVE-2024-1367?
CVE-2024-1367 can be exploited by attackers modifying Logging parameters to execute arbitrary code on the host.
Is authentication required to exploit CVE-2024-1367?
Yes, exploitation of CVE-2024-1367 requires authentication with administrator privileges.