CyberRota Analysis
AI-GeneratedA critical remote code execution vulnerability exists in the report generation functionality of Tenable Security Center, allowing authenticated non-administrative users to exploit the flaw by providing specially crafted input. This could lead to arbitrary code execution with the privileges of the service account, posing significant risks to system integrity and confidentiality. Organizations using Tenable Security Center should prioritize immediate remediation to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report rendering, resulting in arbitrary code execution with the privileges of the service account.