[R1] Stand-alone Security Patch Available for Tenable OT version 4.2.40: tenable-ot-platform-137

0
41

[R1] Stand-alone Security Patch Available for Tenable OT version 4.2.40: tenable-ot-platform-137 Jason Schavel

An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnel user and GatewayPorts. This could be used to potentially glean information about the underlying system and give an attacker information that could be used to attempt to compromise the host.

Out of caution and in line with best practice, Tenable has opted to address the potential impact of the issues. Tenable OT Patch tenable-ot-platform-137 fixes the issues around the misconfiguration to address the identified vulnerability.

– Read more