Tenable Vulnerabilities and Affected Products
Vulnerabilities associated with nessus_agent.
Products
Clear product- Nessus20 vulnerabilities
- Security Center10 vulnerabilities
- Nessus Agent7 vulnerabilities
- Alcatel Lucent I-240W-Q GPON ONT6 vulnerabilities
- ASUSTOR Data Master6 vulnerabilities
- Agent4 vulnerabilities
- Nessus Network Monitor4 vulnerabilities
- nessus_agent4 vulnerabilities
- Tenable Identity Exposure4 vulnerabilities
- Tenable Nessus4 vulnerabilities
- LabKey Server Community Edition3 vulnerabilities
- nessus_network_monitor3 vulnerabilities
- SecurityCenter3 vulnerabilities
- Terrascan3 vulnerabilities
- Network Monitor2 vulnerabilities
- security_center2 vulnerabilities
- Burp Suite Community Edition1 vulnerability
- Check_MK1 vulnerability
- Grandstream GWN70001 vulnerability
- identity_exposure1 vulnerability
- integration-jira-cloud1 vulnerability
- libjpeg-turbo1 vulnerability
- MikroTik RouterOS1 vulnerability
- Tenable Appliance1 vulnerability
- Tenable Identity Exposure Secure Relay1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-3292HIGH | Race ConditionA race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus Agent host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host. - CVE-2024-3292 CWE-367May 17, 2024 | CVSS8.2v3.1 | EPSS0.169% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-3291HIGH | Privilege EscalationWhen installing Nessus Agent to a directory outside of the default location on a Windows host, Nessus Agent versions prior to 10.6.4 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. CWE-281May 17, 2024 | CVSS7.8v3.1 | EPSS0.175% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-2390HIGH | Local Privilege EscalationAs a part of Tenable’s vulnerability disclosure program, a vulnerability in a Nessus plugin was identified and reported. This vulnerability could allow a malicious actor with sufficient permissions on a scan target to place a binary in a specific filesystem location, and abuse the impacted plugin in order to escalate privileges. CWE-269Mar 18, 2024 | CVSS7.8v3.1 | EPSS0.195% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-5847MEDIUM | Under certain conditions, a low privileged attacker could load a specially crafted file during installation or upgrade to escalate privileges on Windows and Linux hosts. CWE-269Nov 1, 2023 | CVSS6.7v3.1 | EPSS0.223% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |