Impact
The vulnerability is a classic SQL injection flaw that allows a privileged attacker to manipulate database queries within Tanium's Asset service. By injecting malicious SQL, an attacker could read, modify, or delete data stored by Asset, thereby compromising confidentiality, integrity, and possibly disrupting availability if critical data is altered. The CVSS score of 7.2 reflects these potential impacts. The vulnerability is tied to CWE-89.
Affected Systems
Tanium Product Suite – Asset component. No specific affected versions are listed, so all deployments using the Asset service are potentially vulnerable until patched.
Risk and Exploitability
The EPSS score of less than 1% indicates a low probability that this flaw is actively exploited in the wild. The vulnerability is not listed in CISA’s KEV catalog, which further suggests limited exploitation. The likely attack vector is remote, as the injection would be triggered through network-accessible Asset interfaces. An attacker would need to provide crafted input to the Asset service, which may require network connectivity and, possibly, authentication depending on deployment. Overall, the risk is moderate because of the CVSS score, but the low EPSS score and absence from KEV reduce the urgency compared to higher‑impact or widely exploited flaws.
OpenCVE Enrichment