Impact
Unvalidated input in the asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low‑privileged operating system user via the Analysis REST endpoint. The weakness is a classic OS command injection (CWE‑78). A successful exploitation would give an attacker the ability to run arbitrary commands on the host running the endpoint, compromising confidentiality, integrity and availability of that environment.
Affected Systems
Tenable, Inc. Security Center. No specific affected-version data was supplied; the flaw exists in all versions prior to the Security Center Patch SC202607.1. The patch is available for download from the Tenable Downloads Portal and addresses the unvalidated input flaw.
Risk and Exploitability
The CVSS score of 9.4 classifies this as a high‑severity vulnerability. The EPSS score of less than 1% indicates that exploitation likelihood is low but not zero. This vulnerability is not listed in CISA’s KEV catalog, so no known active exploits have been reported. The attack vector is inferred to involve sending a crafted request containing malicious asset filter parameters to the Analysis REST endpoint, requiring legitimate API access or network reachability to the endpoint.
OpenCVE Enrichment