« Volver al listado

CVE-2017-8051

Estado: ModificadaCrítica (9.8)—

Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of the tns_appliance_session_user parameter, a remote attacker can inject arbitrary commands.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-8051",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-04-21T18:59:00.317",
  "references": [
    {
      "url": "http://www.tenable.com/security/tns-2017-07",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://vulndb.cyberriskanalytics.com/153135",
      "tags": [
        "Permissions Required"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.exploit-db.com/exploits/41892/",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.tenable.com/security/tns-2017-07",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://vulndb.cyberriskanalytics.com/153135",
      "tags": [
        "Permissions Required"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/41892/",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of the tns_appliance_session_user parameter, a remote attacker can inject arbitrary commands."
    },
    {
      "lang": "es",
      "value": "Tenable Appliance 3.5 - 4.4.0, y, posiblemente, versiones anteriores, contiene un fallo en la secuencia de comandos simpleupload.py en la Web UI. Mediante la manipulación del parámetro tns_appliance_session_user, un atacante remoto puede inyectar comandos arbitrarios."
    }
  ],
  "lastModified": "2026-06-17T01:25:41.750",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:tenable:appliance:3.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "088E231D-5992-4ADD-BA36-1ED9F9A474B8"
            },
            {
              "criteria": "cpe:2.3:a:tenable:appliance:3.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AD287989-729F-4620-AF79-30ADB6A092A5"
            },
            {
              "criteria": "cpe:2.3:a:tenable:appliance:3.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "577B30FC-4CB0-48B7-BC02-D63E896BFF67"
            },
            {
              "criteria": "cpe:2.3:a:tenable:appliance:3.10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DE9FADBB-32BD-4554-825E-77187F966FF2"
            },
            {
              "criteria": "cpe:2.3:a:tenable:appliance:3.10.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DF337FD4-177B-4C13-A94A-89E745792CD0"
            },
            {
              "criteria": "cpe:2.3:a:tenable:appliance:4.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "93F821B1-C5A7-4AA3-8E9D-384C23848B1F"
            },
            {
              "criteria": "cpe:2.3:a:tenable:appliance:4.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D38918B9-AFB5-45AB-A00B-4074771AF649"
            },
            {
              "criteria": "cpe:2.3:a:tenable:appliance:4.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA0B18A3-FBAD-4343-9253-479214175FB6"
            },
            {
              "criteria": "cpe:2.3:a:tenable:appliance:4.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "807211FA-BE46-433F-8D6F-66CFA2868890"
            },
            {
              "criteria": "cpe:2.3:a:tenable:appliance:4.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1140F38C-83AF-4571-8C0F-4BB493A0028E"
            },
            {
              "criteria": "cpe:2.3:a:tenable:appliance:4.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "32DE9C00-60A6-4D42-8C3A-DED6E9D4EDF2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}