Show filters
154 Total Results
Displaying 21-30 of 154
Sort by:
Attacker Value
Unknown

CVE-2024-3291

Disclosure Date: May 17, 2024 (last updated May 18, 2024)
When installing Nessus Agent to a directory outside of the default location on a Windows host, Nessus Agent versions prior to 10.6.4 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.
0
Attacker Value
Unknown

CVE-2024-3290

Disclosure Date: May 17, 2024 (last updated May 18, 2024)
A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host
0
Attacker Value
Unknown

CVE-2024-3289

Disclosure Date: May 17, 2024 (last updated May 18, 2024)
When installing Nessus to a directory outside of the default location on a Windows host, Nessus versions prior to 10.7.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location.
0
Attacker Value
Unknown

CVE-2024-2390

Disclosure Date: March 18, 2024 (last updated January 05, 2025)
As a part of Tenable’s vulnerability disclosure program, a vulnerability in a Nessus plugin was identified and reported. This vulnerability could allow a malicious actor with sufficient permissions on a scan target to place a binary in a specific filesystem location, and abuse the impacted plugin in order to escalate privileges.
0
Attacker Value
Unknown

CVE-2024-1683

Disclosure Date: February 23, 2024 (last updated December 18, 2024)
A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for overriding of the configuration and running of new Secure Relay services.
Attacker Value
Unknown

CVE-2024-1471

Disclosure Date: February 14, 2024 (last updated November 20, 2024)
An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Repository parameters, which could lead to HTML redirection attacks.
Attacker Value
Unknown

CVE-2024-1367

Disclosure Date: February 14, 2024 (last updated November 20, 2024)
A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead to the execution of arbitrary code on the Security Center host.
Attacker Value
Unknown

CVE-2024-0971

Disclosure Date: February 07, 2024 (last updated March 05, 2024)
A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter scan DB content.
Attacker Value
Unknown

CVE-2024-0955

Disclosure Date: February 07, 2024 (last updated February 15, 2024)
A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus proxy settings, which could lead to the execution of remote arbitrary scripts.
Attacker Value
Unknown

CVE-2023-6062

Disclosure Date: November 20, 2023 (last updated November 30, 2023)
An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus Rules variables to overwrite arbitrary files on the remote host, which could lead to a denial of service condition.