CVE-2023-6062

MEDIUM

Nessus < 10.5.7 - Authenticated Arbitrary File Write via Rules Variables

Title source: llm
STIX 2.1

Description

An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus Rules variables to overwrite arbitrary files on the remote host, which could lead to a denial of service condition.

References (2)

Core 2

Scores

CVSS v3 6.8
EPSS 0.0021
EPSS Percentile 43.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (1)
tenable/nessus < 10.5.7
Published Nov 20, 2023
Tracked Since Feb 18, 2026