VDB
CVE-2024-1367
CVE-2024-1367
PUBLISHED
CVSS 7.199999809265137 HIGH
A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead to the execution of arbitrary code on the Security Center host.
EPSS 1.56% · 72.8th percentile
Risk Scores
CVSS 3.1
7.199999809265137
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
1.56%
72.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenable | Security Center | 0, 0 |
| tenable | security_center | 0, 0 |
Timeline
- Feb 14, 2024 CVE Published
- Feb 14, 2024 PoC Published
- Feb 15, 2024 EPSS Score
- Mar 13, 2024 EPSS Score
- Apr 9, 2024 EPSS Score
- Jun 2, 2024 EPSS Score
- Jun 29, 2024 EPSS Score
- Jul 26, 2024 EPSS Score
- Aug 26, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 18, 2024 EPSS Score
- Nov 9, 2024 Coalition ESS Score