CVE-2023-0476

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
26/01/2023
Last modified:
01/04/2025

Description

A LDAP injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An authenticated attacker could generate data in Active Directory using the application account through blind LDAP injection.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:* 5.23.1 (including)