Impact
An improper access control flaw allows an authenticated non-administrative user to view configuration settings that lie outside their intended scope. The vulnerability is a classic example of CWE-1284, where privileges are not enforced correctly. The immediate risk is the exposure of sensitive system configuration, which could aid an attacker in further reconnaissance or exploitation steps.
Affected Systems
Tenable, Inc.'s Security Center product is impacted. All versions prior to Security Center 6.9.0 are potentially vulnerable, as the fix is included in the 6.9.0 release. Users should verify they are running a version newer than 6.8.x to ensure the issue is resolved.
Risk and Exploitability
The CVSS score of 5.3 classifies the flaw as medium severity. Because it requires authentication and is restricted to non-admin users, the attack vector is limited to users who already have legitimate but non-administrative access, either via legitimate credentials or credential compromise. No EPSS data is available, and the vulnerability is not listed in CISA KEV, suggesting there are no known large-scale exploit campaigns targeting it.
OpenCVE Enrichment