85 results (0.006 seconds)

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

21 Mar 2025 — When installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. • https://www.tenable.com/security/tns-2025-02 • CWE-276: Incorrect Default Permissions •

CVSS: 8.4EPSS: 0%CPEs: 1EXPL: 0

30 Sep 2024 — A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI. • https://www.tenable.com/security/tns-2024-17 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.2EPSS: 0%CPEs: 1EXPL: 0

17 May 2024 — A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus Agent host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host. - CVE-2024-3292 Existe una vulnerabilidad de condición de ejecución donde un atacante local autenticado en un host de Nessus Agent de Windows podría modificar los parámetros de instalación en el momento de la instalación, lo que podría conducir a la ejecución de código arb... • https://www.tenable.com/security/tns-2024-09 • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

17 May 2024 — When installing Nessus Agent to a directory outside of the default location on a Windows host, Nessus Agent versions prior to 10.6.4 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. Al instalar Nessus Agent en un directorio fuera de la ubicación predeterminada en un host de Windows, las versiones de Nessus Agent anteriores a la 10.6.4 no aplicaban permisos seguros para lo... • https://www.tenable.com/security/tns-2024-09 • CWE-281: Improper Preservation of Permissions •

CVSS: 8.2EPSS: 0%CPEs: 1EXPL: 0

17 May 2024 — A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host Existe una vulnerabilidad de condición de ejecución donde un atacante local autenticado en un host Nessus de Windows podría modificar los parámetros de instalación en el momento de la instalación, lo que podría llevar a la ejecución de código arbitrario en el host Nessus. • https://www.tenable.com/security/tns-2024-08 • CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

17 May 2024 — When installing Nessus to a directory outside of the default location on a Windows host, Nessus versions prior to 10.7.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. Al instalar Nessus en un directorio fuera de la ubicación predeterminada en un host de Windows, las versiones de Nessus anteriores a la 10.7.3 no aplicaban permisos seguros para los subdirectorios. Esto p... • https://www.tenable.com/security/tns-2024-08 • CWE-281: Improper Preservation of Permissions •

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

18 Mar 2024 — As a part of Tenable’s vulnerability disclosure program, a vulnerability in a Nessus plugin was identified and reported. This vulnerability could allow a malicious actor with sufficient permissions on a scan target to place a binary in a specific filesystem location, and abuse the impacted plugin in order to escalate privileges. Como parte del programa de divulgación de vulnerabilidades de Tenable, se identificó y reportó una vulnerabilidad en un complemento de Nessus. Esta vulnerabilidad podría permitir qu... • https://www.tenable.com/security/tns-2024-05 • CWE-269: Improper Privilege Management •

CVSS: 6.8EPSS: 0%CPEs: 1EXPL: 0

06 Feb 2024 — A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter scan DB content. Existe una vulnerabilidad de inyección SQL en la que un atacante remoto autenticado y con pocos privilegios podría alterar el contenido de la base de datos escaneada. • https://www.tenable.com/security/tns-2024-01 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 0

06 Feb 2024 — A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus proxy settings, which could lead to the execution of remote arbitrary scripts. Existe una vulnerabilidad XSS almacenado donde un atacante remoto autenticado con privilegios de administrador en la aplicación Nessus podría alterar la configuración del proxy de Nessus, lo que podría conducir a la ejecución de scripts arbitrarios remotos. • https://www.tenable.com/security/tns-2024-01 • CWE-20: Improper Input Validation CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.7EPSS: 0%CPEs: 1EXPL: 0

20 Nov 2023 — An arbitrary file write vulnerability exists where an authenticated attacker with privileges on the managing application could alter Nessus Rules variables to overwrite arbitrary files on the remote host, which could lead to a denial of service condition. Existe una vulnerabilidad de escritura de archivos arbitraria donde un atacante autenticado con privilegios en la aplicación de administración podría alterar las variables de Nessus Rules para sobrescribir archivos arbitrarios en el host remoto, lo que pod... • https://www.tenable.com/security/tns-2023-41 • CWE-787: Out-of-bounds Write •