Impact
The vulnerability is an information disclosure flaw in Tanium's Comply product, categorized as CWE‑200. It allows an attacker to gain access to sensitive data that is not intended for public or unauthorized audiences. The CVSS score of 4.3 indicates a medium level of risk; the impact is primarily confidentiality loss.
Affected Systems
The flaw affects Tanium Comply installations, but specific affected versions are not disclosed. Administrators should verify that their deployed version corresponds to the product referenced in Tanium’s advisory.
Risk and Exploitability
Since the EPSS score is not provided and the CVE is not listed in the CISA KEV catalog, the likelihood of exploitation is unclear, though the moderate CVSS score suggests a potential security concern. Attack vectors are not detailed in the advisory, so the exact conditions required for exploitation remain unspecified; the risk is largely tied to the sensitivity of data exposed by Comply and its exposure to potential attackers.
OpenCVE Enrichment