PT-2023-7929 · Tenable · Nessus

Ammarit Thongthua

+1

·

Published

2023-01-20

·

Updated

2023-01-28

·

CVE-2023-0101

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Nessus versions 8.10.1 through 8.15.8 Nessus versions 10.0.0 through 10.4.1
Description The issue is related to insufficient input validation, which can be exploited by a remote attacker to elevate privileges to root or NT AUTHORITY/SYSTEM on the Nessus host. This can be achieved by executing a specially crafted file.
Recommendations For Nessus versions 8.10.1 through 8.15.8, update to a version outside of this range to resolve the issue. For Nessus versions 10.0.0 through 10.4.1, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the Nessus host to minimize the risk of exploitation.

Fix

RCE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2023-09007
CVE-2023-0101

Affected Products

Nessus