CVE-2017-8051
Published Apr 21, 2017
Last updated 5 years ago
Overview
- Description
- Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of the tns_appliance_session_user parameter, a remote attacker can inject arbitrary commands.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-78
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:tenable:appliance:3.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "088E231D-5992-4ADD-BA36-1ED9F9A474B8" }, { "criteria": "cpe:2.3:a:tenable:appliance:3.5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AD287989-729F-4620-AF79-30ADB6A092A5" }, { "criteria": "cpe:2.3:a:tenable:appliance:3.5.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "577B30FC-4CB0-48B7-BC02-D63E896BFF67" }, { "criteria": "cpe:2.3:a:tenable:appliance:3.10.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DE9FADBB-32BD-4554-825E-77187F966FF2" }, { "criteria": "cpe:2.3:a:tenable:appliance:3.10.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DF337FD4-177B-4C13-A94A-89E745792CD0" }, { "criteria": "cpe:2.3:a:tenable:appliance:4.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "93F821B1-C5A7-4AA3-8E9D-384C23848B1F" }, { "criteria": "cpe:2.3:a:tenable:appliance:4.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D38918B9-AFB5-45AB-A00B-4074771AF649" }, { "criteria": "cpe:2.3:a:tenable:appliance:4.2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AA0B18A3-FBAD-4343-9253-479214175FB6" }, { "criteria": "cpe:2.3:a:tenable:appliance:4.3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "807211FA-BE46-433F-8D6F-66CFA2868890" }, { "criteria": "cpe:2.3:a:tenable:appliance:4.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1140F38C-83AF-4571-8C0F-4BB493A0028E" }, { "criteria": "cpe:2.3:a:tenable:appliance:4.4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "32DE9C00-60A6-4D42-8C3A-DED6E9D4EDF2" } ], "operator": "OR" } ] } ]