Lucene search

K
tenableArnie CabralTENABLE:B851B4470BFE6CDEDDBCD2D96BB958C5
HistoryFeb 06, 2024 - 4:07 p.m.

[R1] Nessus Version 10.7.0 Fixes Multiple Vulnerabilities

2024-02-0616:07:31
Arnie Cabral
www.tenable.com
29
nessus
version 10.7.0
fixes
multiple
vulnerabilities
stored xss
remote attacker
administrator privileges
proxy settings
remote arbitrary scripts
sql injection
low-privileged
scan db content
cve-2024-0955
cve-2024-0971

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

18.8%

[R1] Nessus Version 10.7.0 Fixes Multiple Vulnerabilities Arnie Cabral Tue, 02/06/2024 - 11:07

Two separate vulnerabilities were discovered, reported and fixed:

  • A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus proxy settings, which could lead to the execution of remote arbitrary scripts. - CVE-2024-0955
  • A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter scan DB content. - CVE-2024-0971

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

18.8%

Related for TENABLE:B851B4470BFE6CDEDDBCD2D96BB958C5