Impact
A SQL injection flaw exists in Tenable Security Center that enables an authenticated administrator to run arbitrary SQL statements against the system’s database. The vulnerability can lead to unauthorized read or modification of data, including stored credentials, thereby compromising confidentiality and integrity of the collector’s sensitive data.
Affected Systems
The flaw affects Tenable, Inc.’s Security Center. All installations running before the release of version 6.9.0 are potentially vulnerable, as the vendor’s advisory identifies 6.9.0 as the first patched release.
Risk and Exploitability
The CVSS base score of 6.9 signals a moderate impact. Exploitation requires administrator-level credentials; therefore the threat is limited to environments where such access can be obtained, either through credential compromise or insider activity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread public exploitation at the time of this analysis.
OpenCVE Enrichment