CVE-2023-0476
Severity CVSS v4.0:
Pending analysis
Type:
CWE-74
Injection
Publication date:
26/01/2023
Last modified:
01/04/2025
Description
A LDAP injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated attacker could generate data in Active Directory using the application account through blind LDAP injection.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:* | 5.23.1 (including) |
To consult the complete list of CPE names with products and versions, see this page



