VDB
CVE-2024-1367
CVE-2024-1367
PUBLISHED
CVSS 7.199999809265137 HIGH
A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead to the execution of arbitrary code on the Security Center host.
EPSS 1.56% · 74.2th percentile
Risk Scores
CVSS 3.1
7.199999809265137
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
1.56%
74.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenable | Security Center | 0, 0 |
| tenable | security_center | 0, 0 |
Timeline
- Feb 14, 2024 CVE Published
- Feb 14, 2024 PoC Published
- Feb 15, 2024 EPSS Score
- Mar 13, 2024 EPSS Score
- May 7, 2024 EPSS Score
- Jun 3, 2024 EPSS Score
- Jul 1, 2024 EPSS Score
- Aug 28, 2024 EPSS Score
- Sep 24, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 22, 2024 EPSS Score
- Nov 9, 2024 Coalition ESS Score