CVE-2024-1683 HIGH

CVE-2024-1683: DLL Injection in Tenable Identity Exposure Secure Relay

Vendor Tenable
Product Tenable Identity Exposure Secure Relay
Weakness CWE-78
Published February 23, 2024
Last update August 1, 2024

CVSS base score

7.3/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L

What the vulnerability does

01Description

A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for overriding of the configuration and running of new Secure Relay services.

Key dates

02Disclosure timeline

February 23, 2024 CVE published
August 1, 2024 Record updated