An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnel user and GatewayPorts. This could be used to potentially glean information about the underlying system and give an attacker information that could be used to attempt to compromise the host.
Metrics
Affected Vendors & Products
References
History
Wed, 25 Mar 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SSH Misconfiguration Enabling Exfiltration of Service Information in Tenable OT |
Wed, 25 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tenable
Tenable tenable Operation Technology |
|
| Vendors & Products |
Tenable
Tenable tenable Operation Technology |
Tue, 24 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnel user and GatewayPorts. This could be used to potentially glean information about the underlying system and give an attacker information that could be used to attempt to compromise the host. | |
| Weaknesses | CWE-16 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2026-03-25T14:27:17.139Z
Reserved: 2026-03-19T16:38:57.418Z
Link: CVE-2026-4433
Updated: 2026-03-25T14:23:37.008Z
Status : Awaiting Analysis
Published: 2026-03-24T21:16:29.687
Modified: 2026-03-25T15:41:58.280
Link: CVE-2026-4433
No data.