Impact
A command injection flaw allows a remote, unauthenticated attacker to inject and execute arbitrary operating‑system commands with the privileges of the Service Center service account. This weakness, identified as CWE‑78, enables the attacker to exfiltrate data, modify or delete files, install persistent backdoors, and potentially take full control of the host if successful. The vulnerability exists within the Security Center platform and has no authentication guard in the interface that accepts user input for system commands.
Affected Systems
The affected product is Tenable, Inc.: Security Center. All installations released before version 6.9.0 are vulnerable. No specific operating‑system constraints are mentioned, implying all supported OS editions of pre‑6.9.0 builds are at risk.
Risk and Exploitability
The CVSS base score is 9.4, indicating a critical level of severity. EPSS score is 2%, indicating a low yet non‑zero probability for exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no public exploitation yet. However, the attack vector is remote and does not require any authentication, making the threat highly actionable. An attacker who can reach the exposed interface can execute OS commands directly, with a high likelihood of achieving the impact described if no mitigation is in place.
OpenCVE Enrichment