Tenable Security Update – 15 February 2024

Tenable has released a security update to fix multiple vulnerabilities in Tenable Security Center 6.2.1 with Patch SC-202312.1, and earlier.

The addressed vulnerabilities could allow the authenticated remote attacker to perform HTML redirection attacks or execute arbitrary code and gain access to the affected system.

Sample of the addressed vulnerabilities:

Tenable Security Center Command Injection Vulnerability (CVE-2024-1367):

  • CVSS: 7.2
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities
  • CVE-2024-1367
  • CVE-2024-1471
  • CVE-2023-7104
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Tenable Security Update

References