Back to search
CVE-2022-4313
Published: Mar 15, 2023
Modified: Feb 27, 2025
PUBLISHED
Description
A vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, that has Scan Policy Configuration roles, could manipulate audit policy variables to execute arbitrary commands on credentialed scan targets.
| Vendor | Product | Versions |
|---|---|---|
n/a | Tenable.io, Tenable.sc and Nessus | affected Plugin Feed Version 202212081951 and earlier |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now