Impact
Path traversal flaw in Tenable Agent 11.2.0, 11.1.3, and earlier allows a privileged attacker to write files outside the intended plugin directory. This can enable the attacker to place arbitrary executables or scripts, leading to remote code execution on the affected host. The vulnerability is a classic directory traversal (CWE-22) combined with improper write control (CWE-347).
Affected Systems
The affected product is Tenable Agent from Tenable, Inc., specifically versions 11.2.0, 11.1.3, and all earlier releases.
Risk and Exploitability
The CVSS score of 9.3 denotes critical severity, but the EPSS score of less than 1% indicates a low probability of exploitation at this time. The flaw requires a privileged attacker; the advisory does not explicitly exclude remote exploitation, so remote attackers could potentially exploit if they gain sufficient privileges. The vulnerability is not listed in CISA KEV catalog, suggesting no publicly known active exploits have yet been reported. Nonetheless, organizations running vulnerable agent versions should treat this as a top-priority issue due to the high impact of potential remote code execution.
OpenCVE Enrichment