CVE-2023-3252

MEDIUM

Tenable Nessus < 10.6.0 - Uncontrolled Search Path

Title source: rule

Description

An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges could alter logging variables to overwrite arbitrary files on the remote host with log data, which could lead to a denial of service condition.

Scores

CVSS v3 6.8
EPSS 0.0021
EPSS Percentile 42.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

Classification

CWE
CWE-427
Status published

Affected Products (1)

tenable/nessus < 10.6.0

Timeline

Published Aug 29, 2023
Tracked Since Feb 18, 2026