Impact
The vulnerability in Tanium Server allows an unintended disclosure of sensitive information. It is classified as Information Exposure (CWE‑200) and carries a CVSS score of 4.3, a moderate severity that denotes a risk to confidentiality. The advisory does not specify the exact data that might be exposed, but the nature of the weakness suggests that any confidential data that the server stores or handles could be read by an attacker.
Affected Systems
This issue affects the Tanium Server component of the Tanium platform. The advisory does not list specific product versions; it states that all installations should be updated once the vendor provides a patch. The affected product is Tanium Server as identified by the vendor CNA.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk, and the EPSS score is not available, so there is no evidence of widespread exploitation. The vulnerability is not recorded in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector requires network access to the Tanium Server and sufficient privileges to read the exposed data, but the precise conditions are not detailed in the advisory.
OpenCVE Enrichment