Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-4313


A vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, that has Scan Policy Configuration roles, could manipulate audit policy variables to execute arbitrary commands on credentialed scan targets.


Published

2023-03-15T23:15:09.337

Last Modified

2025-02-27T19:15:47.290

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-427

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application tenable nessus < 10.4.2 Yes
Application tenable plugin_feed < 202212081952 Yes

References