[R1] SecurityCenter 5.7.1 Fixes Multiple Third-Party Vulnerabilities

Related Vulnerabilities: CVE-2018-0732   CVE-2018-0737   CVE-2018-14883   CVE-2018-14851   CVE-2018-15132   CVE-2018-10549   CVE-2018-10548   CVE-2018-10547   CVE-2018-10546   CVE-2018-10545   CVE-2018-7584  

SecurityCenter leverages third-party software to help provide underlying functionality. Two separate third-party components (PHP and OpenSSL) were found to contain vulnerabilities, and updated versions have been made available by the providers. Out of caution and in line with good practice, Tenable opted to upgrade the bundled libraries to address the potential impact of these issues in SecurityCenter. SecurityCenter 5.7.1 updates PHP to version 7.1.21 and OpenSSL to version 1.0.2o to address the identified vulnerabilities. Note: The CVSSv2 score used in this advisory reflects CVE-2018-7584, as it is considered the highest risk.

Synopsis

SecurityCenter leverages third-party software to help provide underlying functionality. Two separate third-party components (PHP and OpenSSL) were found to contain vulnerabilities, and updated versions have been made available by the providers.

Out of caution and in line with good practice, Tenable opted to upgrade the bundled libraries to address the potential impact of these issues in SecurityCenter. SecurityCenter 5.7.1 updates PHP to version 7.1.21 and OpenSSL to version 1.0.2o to address the identified vulnerabilities.

Note: The CVSSv2 score used in this advisory reflects CVE-2018-7584, as it is considered the highest risk.

Solution

Tenable has released SecurityCenter 5.7.1 to address these issues. The installation files can be obtained from the Tenable Downloads Portal (https://www.tenable.com/downloads/securitycenter-3d-tool-and-xtool)