Tenable Security Updates 14 March 2023

Tenable has released security updates to fix a critical vulnerability in Tenable.sc, tenable.io, and Nessus.

The addressed vulnerability could allow the authenticated attacker to modify the scan variables, and manipulate audit policy variables to execute arbitrary commands on credentialed scan targets.

Tenable Plugin Arbitrary Code Execution Vulnerability (CVE-2022-4313):

• CVSS: 9.1

• Attack Vector: Network

• Attack Complexity: Low

• Privileges Required: High

• User Interaction: None

• Consequences: Gain Access

Vulnerabilities
  • CVE-2022-4313
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Tenable Security Advisory

References