SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2026-4433

This could be used to potentially glean information about the underlying system and give an attacker information that could be used to attempt to compromise the host.

LOW 1.9EPSS 0.16%

Does this matter?

Lower severity and a low EPSS score (0.16%). Track it; it rarely justifies an emergency change on its own.

Description

An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnel user and GatewayPorts. This could be used to potentially glean information about the underlying system and give an attacker information that could be used to attempt to compromise the host.

CVSS 4.0
1.9 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
0.16% probability · 6th percentile
CISA KEV
Not listed
Weakness
CWE-16
Affected
tenable/operational technology exposure
Source
vulnreport@tenable.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.