Impact
An input validation flaw in Tenable Security Center’s file upload handling allows an attacker to supply a malicious file name that is not properly sanitized, potentially leading to shell command execution on the host. The vulnerability is identified as an operating‑system command injection (CWE‑78). If exploited, arbitrary commands can run with the privileges of the application, enabling full compromise of the impacted systems.
Affected Systems
Tenable Inc. Security Center versions released before 6.9.0 are affected. The flaw is located in the component that processes file uploads and does not appear in later releases.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.7, signifying high severity. EPSS score of 1.56% and it is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, accessed through the web‑based file upload interface, and an adversary with upload access could craft a filename that triggers unintended command execution, thereby breaking confidentiality, integrity, and availability.
OpenCVE Enrichment