Impact
Tanium Enforce contains a server‑side request forgery flaw, classified as CWE‑918. This weakness allows an attacker to instruct the Enforce server to fetch arbitrary resources over HTTP or other protocols, potentially exposing internal data or facilitating further compromise. The primary impact is that an adversary could gain unintended access to internal services, retrieve sensitive information, or pivot within the network.
Affected Systems
The vulnerability affects Tanium Enforce. No specific affected versions are listed in the advisory, so all deployed instances of Enforce should be considered vulnerable until a patch is confirmed installed.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity, and the lack of an EPSS score or KEV listing suggests the vulnerability has not yet been widely exploited but remains a serious risk. Attackers likely need network access to the compromised Enforce instance and may use the SSRF path to reach internal resources that are otherwise unreachable from the outside. Without mitigation, the flaw could be utilized to read or modify data on internal services, bypassing normal access controls.
OpenCVE Enrichment