CVE-2018-1148

MEDIUM

Nessus <7.1.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

In Nessus before 7.1.0, Session Fixation exists due to insufficient session management within the application. An authenticated attacker could maintain system access due to session fixation after a user password change.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://www.tenable.com/security/tns-2018-05
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1040918

Scores

CVSS v3 6.5
EPSS 0.0016
EPSS Percentile 36.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-384
Status published
Products (1)
tenable/nessus < 7.1.0
Published May 18, 2018
Tracked Since Feb 18, 2026