Impact
The vulnerability is an information disclosure flaw in Tanium Connect, classified under CWE-214. Attackers could retrieve sensitive data that is not intended to be exposed, potentially compromising confidentiality. The description does not state the extent of data that can be extracted, but the impact is limited to the data that Tanium Connect stores or passes.
Affected Systems
Tanium Connect is affected. No specific version information is provided by the CNA, so all installations of Tanium Connect are potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate risk, and the EPSS score of less than 1% shows that there is a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is through local or network access to the Connect service, but this is inferred rather than stated in the public advisory.
OpenCVE Enrichment