Impact
The vulnerability resides in Tenable Security Center's report filtering functionality, where unsanitized user‑supplied input is directly concatenated into SQL queries. This allows an attacker to inject crafted payloads, leading to blind SQL injection and unauthorized read access to the application's database, potentially exposing confidential data and compromising database integrity and confidentiality.
Affected Systems
Tenable Security Center from Tenable, Inc. All versions prior to the patch SC202607.1 are affected, as the advisory does not specify a narrower version range.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in CISA's KEV catalog. Based on the description, the likely attack vector is through the web interface’s report filtering parameters, where an attacker can craft inputs that bypass parameterization to read database contents.
OpenCVE Enrichment