Tenable.Sc
Vendor:
First CVE: Feb 20, 2019 · Active for 7 years
46
Total CVEs
More Total CVEs than 97% of tracked products
9.2
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 48% of tracked products
4.3%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Tenable.Sc over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 20, 2019
7 years ago
Most Recent CVE
Feb 1, 2023
1,269 days ago
CVE Severity & Scoring
Tenable.Sc46 CVEs
39%
35%
24%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (4.3%)
Network44 (95.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low40 (87.0%)
High6 (13.0%)
Unknown0 (0.0%)
User Interaction
None33 (71.7%)
Unknown0 (0.0%)
Required13 (28.3%)
Privileges Required
Low9 (19.6%)
High1 (2.2%)
None36 (78.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (46 CVEs).
46 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11043CRITICAL In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buff | Oct 28, 2019 | 9.8 | 98 | YES | YES |
CVE-2021-40438CRITICAL A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | Sep 16, 2021 | 9.0 | 97 | YES | YES |
CVE-2021-44790CRITICAL A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an explo | Dec 20, 2021 | 9.8 | 88 | NO | YES |
CVE-2021-3711CRITICAL In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first tim | Aug 24, 2021 | 9.8 | 79 | NO | NO |
CVE-2021-44224HIGH A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy de | Dec 20, 2021 | 8.2 | 72 | NO | NO |
CVE-2021-34798HIGH Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier. | Sep 16, 2021 | 7.5 | 61 | NO | NO |
CVE-2021-3449MEDIUM An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms | Mar 25, 2021 | 5.9 | 57 | NO | NO |
CVE-2021-3712HIGH ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This cont | Aug 24, 2021 | 7.4 | 53 | NO | NO |
CVE-2021-33193HIGH A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Se | Aug 16, 2021 | 7.5 | 50 | NO | NO |
CVE-2021-41184MEDIUM jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execut | Oct 26, 2021 | 6.1 | 42 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (46 CVEs).
CISA KEV
2 CVEs
4.3% of CVEs· 97th percentile
Metasploit
1 CVE
2.2% of CVEs· 96th percentile
Nuclei
1 CVE
2.2% of CVEs· 96th percentile
ExploitDB
2 CVEs
4.3% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (46 CVEs).
Media Mentions
Signals from CVEs in this product scope (46 CVEs).
Top CNAs Publishing CVEs For Tenable.Sc
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.19.0 | 1 | 4.3 | 2.8% | 0 | 0 |
| 5.14.1 | 1 | 5.4 | 0.6% | 0 | 0 |
| 5.14.0 | 1 | 5.4 | 0.6% | 0 | 0 |