Impact
A command injection flaw in Tenable Security Center allows an authenticated administrator to alter application configuration values. When certain backend operations run, the manipulated configuration leads to arbitrary command execution on the underlying operating system. The weakness is a classic command injection (CWE‑78) and enables the attacker to compromise the host with the permissions of the application process.
Affected Systems
The vulnerability affects Tenable, Inc.'s Security Center application. The specific affected versions are not enumerated in the advisory, so any deployment of Security Center that has not been updated to the latest release is potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.6 reflects high severity with a possibility of full system compromise. EPSS data is not available, but the flaw requires authenticated access, meaning exploitation hinges on compromised or misused administrative credentials. The vulnerability is not listed in CISA’s KEV catalog at this time. An attacker who gains administrator rights can execute arbitrary code on the server once the relevant backend process is invoked.
OpenCVE Enrichment