Impact
An authenticated command injection flaw exists in Tenable Security Center related to how the system processes uploaded files. A malicious user who can upload files can craft the content of the file such that commands are executed on the underlying operating system. This enables arbitrary command execution, allowing a threat actor to compromise system confidentiality, integrity, and availability across the entire environment where Security Center runs. The weakness is a classic OS command injection (CWE‑78).
Affected Systems
Tenable, Inc. Security Center—prior to release 6.9.0. All deployments that have not applied that update are potentially vulnerable, as the flaw pertains to file upload handling throughout the product. No specific sub‑version numbers are listed, so any instance that predates the 6.9.0 patch is considered affected.
Risk and Exploitability
The CVSS v3 score of 9.4 denotes a high‑severity vulnerability. Because EPSS is not available, exploitation likelihood is unknown, but the flaw is listed as non‑KEV, implying no publicly available exploit is cataloged yet. The attack vector is inferred to be authenticated: a user must be logged into Security Center to upload a file that triggers the injection. Even though the official description does not detail the exact command syntax, the impact is clear—arbitrary OS commands can be executed with the privileges of the Security Center service.
OpenCVE Enrichment