PT-2022-18936 · Tenable · Nessus Essentials+2

Published

2022-10-17

·

Updated

2025-05-13

·

CVE-2022-28291

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nessus Essentials and Professional (affected versions not specified)
Description The issue allows an authenticated user with debug privileges to retrieve stored Nessus policy credentials from the "nessusd" process in cleartext via process dumping. This could enable an attacker to access credentials stored in Nessus scanners, potentially compromising the customers' network of assets.
Recommendations For all versions of Nessus Essentials and Professional, consider restricting debug privileges to minimize the risk of exploitation. As a temporary workaround, limit access to the "nessusd" process to prevent unauthorized credential retrieval. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2022-28291

Affected Products

Nessus
Nessus Essentials
Nessus Professional