PT-2024-39461 · Tenable · Nessus Network Monitor

Published

2024-09-30

·

Updated

2024-10-07

·

CVE-2024-9158

CVSS v3.1

8.4

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nessus Network Monitor versions 6.4.1 and earlier
Description A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI. This allows the attacker to execute arbitrary code.
Recommendations For Nessus Network Monitor versions 6.4.1 and earlier, update to a version later than 6.4.1 to resolve the issue. As a temporary workaround, consider restricting access to the local CLI to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-9158

Affected Products

Nessus Network Monitor