CVE-2017-11508
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans. An attacker could exploit this vulnerability by entering a crafted SQL query into the password field of a diagnostic scan within SecurityCenter. Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access.
Las versiones 5.5.0, 5.5.1 y 5.5.2 de SecurityCenter contienen una vulnerabilidad de inyección SQL que podría explotarse por un usuario autenticado con los privilegios suficientes para ejecutar análisis de diagnóstico. Un atacante podría explotar esta vulnerabilidad introduciendo una consulta SQL manipulada en el campo password de un análisis de diagnóstico en SecurityCenter. La explotación exitosa de esta vulnerabilidad podría permitir que un atacante obtenga acceso no autorizado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-07-21 CVE Reserved
- 2017-11-02 CVE Published
- 2023-03-08 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1039804 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.tenable.com/security/tns-2017-13 | 2017-11-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Tenable Search vendor "Tenable" | Securitycenter Search vendor "Tenable" for product "Securitycenter" | 5.5.0 Search vendor "Tenable" for product "Securitycenter" and version "5.5.0" | - |
Affected
| ||||||
Tenable Search vendor "Tenable" | Securitycenter Search vendor "Tenable" for product "Securitycenter" | 5.5.1 Search vendor "Tenable" for product "Securitycenter" and version "5.5.1" | - |
Affected
| ||||||
Tenable Search vendor "Tenable" | Securitycenter Search vendor "Tenable" for product "Securitycenter" | 5.5.2 Search vendor "Tenable" for product "Securitycenter" and version "5.5.2" | - |
Affected
|