PT-2023-7929 · Tenable · Nessus
Ammarit Thongthua
+1
·
Published
2023-01-20
·
Updated
2023-01-28
·
CVE-2023-0101
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Nessus versions 8.10.1 through 8.15.8
Nessus versions 10.0.0 through 10.4.1
Description
The issue is related to insufficient input validation, which can be exploited by a remote attacker to elevate privileges to root or NT AUTHORITY/SYSTEM on the Nessus host. This can be achieved by executing a specially crafted file.
Recommendations
For Nessus versions 8.10.1 through 8.15.8, update to a version outside of this range to resolve the issue.
For Nessus versions 10.0.0 through 10.4.1, update to a version outside of this range to resolve the issue.
As a temporary workaround, consider restricting access to the Nessus host to minimize the risk of exploitation.
Fix
RCE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nessus