Lucene search

K
cve[email protected]CVE-2023-6178
HistoryNov 20, 2023 - 9:15 p.m.

CVE-2023-6178

2023-11-2021:15:08
CWE-787
web.nvd.nist.gov
26
cve-2023-6178
arbitrary file write
nessus rules
denial of service
vulnerability
nvd

6.8 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

6.4 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

15.9%

An arbitrary file write vulnerability exists where an authenticated attacker with privileges on the managing application could alter Nessus Rules variables to overwrite arbitrary files on the remote host, which could lead to a denial of service condition.

Affected configurations

NVD
Node
tenablenessusRange<10.4.4
CPENameOperatorVersion
tenable:nessustenable nessuslt10.4.4

CNA Affected

[
  {
    "defaultStatus": "affected",
    "product": "Nessus Agent",
    "vendor": "Tenable",
    "versions": [
      {
        "lessThan": "10.4.3",
        "status": "affected",
        "version": "0",
        "versionType": "10.4.4"
      }
    ]
  }
]

6.8 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

6.4 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

15.9%

Related for CVE-2023-6178