Tenable Security Center
cpe:2.3:a:tenable:security_center:*:*:*:*:*:*:*
- <= 6.7.2
A privilege escalation vulnerability has been identified in Tenable Security Center versions through 6.7.2. This vulnerability arises from an Indirect Object Reference (IDOR) issue, where an authenticated remote attacker can manipulate the 'owner' parameter to escalate privileges.
Exploitation of this vulnerability allows for unauthorized privilege escalation, enabling users to gain elevated rights or access within the application.
Tenable has released Security Center version 6.8.0 to address this vulnerability. The update can be downloaded from the Tenable Downloads Portal. Users should also refer to the Tenable SC Release Notes for additional information.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.