CVE-2024-3232
Estado: AnalizadaMedia (6.8)—
A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could manipulate application form fields in order to trick another administrator into executing CSV payloads. - CVE-2024-3232
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.47%
- Percentil entre todas las CVEs puntuadas: 38
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-1236
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-3232",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-3232",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-07-16T19:12:59.960894Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "vulnreport@tenable.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 7.6,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.8,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.9
}
]
},
"affected": [
{
"source": "vulnreport@tenable.com",
"affectedData": [
{
"vendor": "Tenable",
"product": "Tenable Identity Exposure",
"versions": [
{
"status": "affected",
"version": "Tenable Identity Exposure 3.42"
},
{
"status": "affected",
"version": "Tenable Identity Exposure 3.29"
},
{
"status": "affected",
"version": "Tenable Identity Exposure 3.19"
}
],
"platforms": [
"Windows"
],
"defaultStatus": "affected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:tenable:identity_exposure:3.19:*:*:*:*:*:*:*"
],
"vendor": "tenable",
"product": "identity_exposure",
"versions": [
{
"status": "affected",
"version": "3.19"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:tenable:identity_exposure:3.29:*:*:*:*:*:*:*"
],
"vendor": "tenable",
"product": "identity_exposure",
"versions": [
{
"status": "affected",
"version": "3.29"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:tenable:identity_exposure:3.42:*:*:*:*:*:*:*"
],
"vendor": "tenable",
"product": "identity_exposure",
"versions": [
{
"status": "affected",
"version": "3.42"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-07-16T17:15:11.267",
"references": [
{
"url": "https://www.tenable.com/security/tns-2024-04",
"tags": [
"Vendor Advisory"
],
"source": "vulnreport@tenable.com"
},
{
"url": "https://www.tenable.com/security/tns-2024-04",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "vulnreport@tenable.com",
"description": [
{
"lang": "en",
"value": "CWE-1236"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could manipulate application form fields in order to trick another administrator into executing CSV payloads. - CVE-2024-3232"
},
{
"lang": "es",
"value": "Existe una vulnerabilidad de inyección de fórmula en Tenable Identity Exposure donde un atacante remoto autenticado con privilegios administrativos podría manipular los campos del formulario de solicitud para engañar a otro administrador para que ejecute payloads CSV. - CVE-2024-3232"
}
],
"lastModified": "2026-06-17T07:43:35.043",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tenable:identity_exposure:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "41048D01-1264-4CB2-972C-276B47FAA192",
"versionEndExcluding": "3.59.4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "vulnreport@tenable.com"
}