René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

82 lines
2.2 KiB
JSON

{
"id": "CVE-2022-4313",
"sourceIdentifier": "vulnreport@tenable.com",
"published": "2023-03-15T23:15:09.337",
"lastModified": "2023-03-24T16:15:01.650",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, that has Scan Policy Configuration roles, could manipulate audit policy variables to execute arbitrary commands on credentialed scan targets."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:tenable:nessus:*:*:*:*:*:*:*:*",
"versionEndExcluding": "10.4.2",
"matchCriteriaId": "1D243271-6ED5-4CA4-AB61-DD5526066E4D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:tenable:plugin_feed:*:*:*:*:*:*:*:*",
"versionEndExcluding": "202212081952",
"matchCriteriaId": "67B40173-E59F-4DC9-BB7E-6C0CAE1725FC"
}
]
}
]
}
],
"references": [
{
"url": "https://www.tenable.com/security/tns-2023-14",
"source": "vulnreport@tenable.com",
"tags": [
"Vendor Advisory"
]
}
]
}