Lucene search

K
cvelistTenableCVELIST:CVE-2023-5624
HistoryOct 26, 2023 - 4:36 p.m.

CVE-2023-5624 Blind SQL Injection

2023-10-2616:36:32
CWE-20
tenable
www.cve.org
4
nessus network monitor
blind sql
injection
vulnerability

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

7.9

Confidence

High

EPSS

0.001

Percentile

24.9%

Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow an admin user to alter parameters that could potentially allow a blindSQL injection.

CNA Affected

[
  {
    "defaultStatus": "affected",
    "product": "Nessus Network Monitor",
    "vendor": "Tenable",
    "versions": [
      {
        "lessThan": "6.3.0",
        "status": "affected",
        "version": "0",
        "versionType": "6.3.0"
      }
    ]
  }
]

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

7.9

Confidence

High

EPSS

0.001

Percentile

24.9%