Home

Description

An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnel user and GatewayPorts. This could be used to potentially glean information about the underlying system and give an attacker information that could be used to attempt to compromise the host.

PUBLISHED Reserved 2026-03-19 | Published 2026-03-24 | Updated 2026-03-25 | Assigner tenable




LOW: 1.9CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

Problem types

CWE-16: Configuration

Product status

Default status
unaffected

3.18.58 (custom)
affected

References

www.tenable.com/security/tns-2026-9

cve.org (CVE-2026-4433)

nvd.nist.gov (CVE-2026-4433)

Download JSON