A vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, that has Scan Policy Configuration roles, could manipulate audit policy variables to execute arbitrary commands on credentialed scan targets.
History

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 27 Feb 2025 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-427

cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2025-02-27T18:35:57.540Z

Reserved: 2022-12-06T00:00:00.000Z

Link: CVE-2022-4313

cve-icon Vulnrichment

Updated: 2024-08-03T01:34:50.145Z

cve-icon NVD

Status : Modified

Published: 2023-03-15T23:15:09.337

Modified: 2025-02-27T19:15:47.290

Link: CVE-2022-4313

cve-icon Redhat

No data.