vendor:
Tenable Appliance
by:
agix
9,8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Tenable Appliance
Affected Version From: < 4.5
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: a:tenable:tenable_appliance
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Tenable Appliance 3.5
2017
Unauthenticated remote root code execution on Tenable Appliance
This exploit allows an unauthenticated attacker to execute arbitrary code on Tenable Appliance versions prior to 4.5. The attacker can send a maliciously crafted HTTP request to the vulnerable web interface, which will execute a bash shell and open a reverse shell to the attacker's machine.
Mitigation:
Upgrade to Tenable Appliance version 4.5 or later.