CVE-2024-1683: DLL Injection in Tenable Identity Exposure Secure Relay
A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for overriding of the configuration and running of new Secure Relay services.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Tenable Identity Exposure Secure Relayto a version that resolves this vulnerability.Fixed in 3.59.4
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1683?
CVE-2024-1683 is classified as a medium severity vulnerability due to its potential impact on system configuration and service integrity.
How do I fix CVE-2024-1683?
To address CVE-2024-1683, it is recommended to update to Tenable Identity Exposure version 3.59.4 or higher.
Who is affected by CVE-2024-1683?
CVE-2024-1683 affects users of Tenable Identity Exposure versions prior to 3.59.4.
What are the risks associated with CVE-2024-1683?
The risks associated with CVE-2024-1683 include unauthorized modification of application files and potential execution of malicious services.
Is authentication required to exploit CVE-2024-1683?
Yes, CVE-2024-1683 requires an authenticated, low-privileged local attacker to exploit the vulnerability.