CVE-2023-3252
MEDIUMTenable Nessus < 10.6.0 - Uncontrolled Search Path
Title source: ruleDescription
An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges could alter logging variables to overwrite arbitrary files on the remote host with log data, which could lead to a denial of service condition.
Scores
CVSS v3
6.8
EPSS
0.0021
EPSS Percentile
42.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
Classification
CWE
CWE-427
Status
published
Affected Products (1)
tenable/nessus
< 10.6.0
Timeline
Published
Aug 29, 2023
Tracked Since
Feb 18, 2026