CVE-2022-4313

HIGH

Nessus < 10.4.2 - Authenticated Remote Code Execution via Scan Variable Manipulation

Title source: llm
STIX 2.1

Description

A vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, that has Scan Policy Configuration roles, could manipulate audit policy variables to execute arbitrary commands on credentialed scan targets.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0089
EPSS Percentile 75.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (2)
tenable/nessus < 10.4.2
tenable/plugin_feed < 202212081952
Published Mar 15, 2023
Tracked Since Feb 18, 2026