CVE-2024-9158
HIGHTenable Nessus Network Monitor < 6.5.0 - XSS
Title source: ruleDescription
A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI.
Scores
CVSS v3
8.4
EPSS
0.0031
EPSS Percentile
53.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Classification
CWE
CWE-79
Status
published
Affected Products (1)
tenable/nessus_network_monitor
< 6.5.0
Timeline
Published
Sep 30, 2024
Tracked Since
Feb 18, 2026