---
id: CVE-2017-11508
title: >-
  SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection
  vulnerability that could be exploited by an authenticated user with sufficient
  privileges to run diagnostic scans
summary: >-
  SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection
  vulnerability that could be exploited by an authenticated user with sufficient
  privileges to run diagnostic scans. An attacker could exploit this
  vulnerability by ent…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
vendor: tenable
product: security_center
affected:
  - security_center = 5.5.0
  - security_center = 5.5.1
  - security_center = 5.5.2
published: '2017-11-02'
updated: '2026-08-17'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2017-11508'
references:
  - url: 'http://www.securitytracker.com/id/1039804'
    label: vulnreport@tenable.com
  - url: 'https://www.tenable.com/security/tns-2017-13'
    label: vulnreport@tenable.com
  - url: 'http://www.securitytracker.com/id/1039804'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.tenable.com/security/tns-2017-13'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01031
epssPercentile: 0.61727
ingestedAt: '2026-08-17T14:55:58.614Z'
---

## Overview

SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans. An attacker could exploit this vulnerability by entering a crafted SQL query into the password field of a diagnostic scan within SecurityCenter. Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access.

## Affected

- `security_center = 5.5.0`
- `security_center = 5.5.1`
- `security_center = 5.5.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
