Vulnerability Description
SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans. An attacker could exploit this vulnerability by entering a crafted SQL query into the password field of a diagnostic scan within SecurityCenter. Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenable | Securitycenter | 5.5.0 |
Related Weaknesses (CWE)
References
- http://www.securitytracker.com/id/1039804Third Party AdvisoryVDB Entry
- https://www.tenable.com/security/tns-2017-13Vendor Advisory
- http://www.securitytracker.com/id/1039804Third Party AdvisoryVDB Entry
- https://www.tenable.com/security/tns-2017-13Vendor Advisory
FAQ
What is CVE-2017-11508?
CVE-2017-11508 is a vulnerability with a CVSS score of 8.8 (HIGH). SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans. An attacker co...
How severe is CVE-2017-11508?
CVE-2017-11508 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-11508?
Check the references section above for vendor advisories and patch information. Affected products include: Tenable Securitycenter.