Impact
The vulnerability allows an attacker to embed shell metacharacters in a filename supplied during file upload, which the system subsequently passes to a shell command unfiltered. This results in arbitrary command execution and can compromise the entire system with elevated privileges. The weakness is classified as CWE-78, reflecting command injection through improper sanitization.
Affected Systems
The issue is present in Tenable, Inc. Security Center. No; the vendor has provided a patch to address the flaw.
Risk and Exploitability
The flaw bears a CVSS score of 9.4, indicating high severity, and an EPSS score of 3%, suggesting a moderate likelihood of exploitation. It is not listed in CISA KEV. The available description implies that the injection can be achieved via the audit file upload functionality, likely requiring authenticated access or privileged user execution to reach the system shell.
OpenCVE Enrichment