CVE-2023-5624

HIGH

Nessus Network Monitor < 6.3.0 - Authenticated Blind SQL Injection via Parameter Alteration

Title source: llm
STIX 2.1

Description

Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow an admin user to alter parameters that could potentially allow a blindSQL injection.

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0009
EPSS Percentile 24.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (1)
tenable/nessus_network_monitor < 6.3.0
Published Oct 26, 2023
Tracked Since Feb 18, 2026