CVE-2023-3252

MEDIUM

Nessus < 10.6.0 - Authenticated Arbitrary File Write via Logging Variables

Title source: llm
STIX 2.1

Description

An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges could alter logging variables to overwrite arbitrary files on the remote host with log data, which could lead to a denial of service condition.

References (1)

Core 1
Core References

Scores

CVSS v3 6.8
EPSS 0.0026
EPSS Percentile 49.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-427
Status published
Products (1)
tenable/nessus < 10.6.0
Published Aug 29, 2023
Tracked Since Feb 18, 2026