CVE-2022-4313
Last modified
CVE-2022-4313 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, that has Scan Policy Configuration roles, could manipulate audit policy variables to execute arbitrary commands on credentialed scan targets.. EPSS estimates a 1.24% chance of exploitation in the next 30 days.
Description
A vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, that has Scan Policy Configuration roles, could manipulate audit policy variables to execute arbitrary commands on credentialed scan targets.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tenable | Nessus | < 10.4.2 |
| Tenable | Plugin Feed | < 202212081952 |
References
- https://www.tenable.com/security/tns-2023-14Vendor Advisory
- https://www.tenable.com/security/tns-2023-14Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-4313?
How severe is CVE-2022-4313?
How do I fix CVE-2022-4313?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-43121A cross-site scripting (XSS) vulnerability in the CMS Field …6.1
- CVE-2022-43124Online Diagnostic Lab Management System v1.0 was discovered …7.2
- CVE-2022-43125Online Diagnostic Lab Management System v1.0 was discovered …7.2
- CVE-2022-43126Online Diagnostic Lab Management System v1.0 was discovered …7.2
- CVE-2022-43127Online Diagnostic Lab Management System v1.0 was discovered …7.2
- CVE-2022-43128Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE…
- CVE-2022-43135Online Diagnostic Lab Management System v1.0 was discovered …9.8
- CVE-2022-43138Dolibarr Open Source ERP & CRM for Business before v14.0.1 a…9.8
- CVE-2022-4314Improper Privilege Management in GitHub repository ikus060/r…9.8
- CVE-2022-43140kkFileView v4.1.0 was discovered to contain a Server-Side Re…7.5
- CVE-2022-43142A cross-site scripting (XSS) vulnerability in the add-fee.ph…6.1
- CVE-2022-43143A cross-site scripting (XSS) vulnerability in Beekeeper Stud…9.6
Are you affected by CVE-2022-4313?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
