Impact
The vulnerability resides in Tanium Discover, allowing an attacker to obtain restricted information through improper access controls. An attacker who can reach the Discover interface may view sensitive data that should be restricted. The weakness is classified as CWE‑200. The impact is a compromise of confidentiality, with no evidence of code execution or denial of service.
Affected Systems
The flaw affects the Tanium Discover product. No specific version range is provided in the advisory, so any deployment using Tanium Discover remains potentially vulnerable until verified that the fix is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a very low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, implying it has no known active exploits. Attackers who can access the Discover interface would need valid credentials or local network access, so the attack vector is likely network-based. Overall risk remains moderate but with low exploitation likelihood.
OpenCVE Enrichment