Vulnerability Details CVE-2023-24495
A Server Side Request Forgery (SSRF) vulnerability exists in Tenable.sc due to improper validation of session & user-accessible input data. A privileged, authenticated remote attacker could interact with external and internal services covertly.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 30.5%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2023-24495
-
cpe:2.3:a:tenable:tenable.sc:-
-
cpe:2.3:a:tenable:tenable.sc:5.13.0
-
cpe:2.3:a:tenable:tenable.sc:5.14.0
-
cpe:2.3:a:tenable:tenable.sc:5.14.1
-
cpe:2.3:a:tenable:tenable.sc:5.16.0
-
cpe:2.3:a:tenable:tenable.sc:5.17.0
-
cpe:2.3:a:tenable:tenable.sc:5.18.0
-
cpe:2.3:a:tenable:tenable.sc:5.19.0
-
cpe:2.3:a:tenable:tenable.sc:5.19.1
-
cpe:2.3:a:tenable:tenable.sc:5.20.0
-
cpe:2.3:a:tenable:tenable.sc:5.20.1
-
cpe:2.3:a:tenable:tenable.sc:5.21.0
-
cpe:2.3:a:tenable:tenable.sc:5.23.1