CVE-2014-4980: Infoleak
Published Jul 23, 2014
·Updated
The /server/properties resource in Tenable Web UI before 2.3.5 for Nessus 5.2.3 through 5.2.7 allows remote attackers to obtain sensitive information via the token parameter.
Affected Software
6 affected components
Tenable Nessus=5.2.3
Tenable Nessus=5.2.4
Tenable Nessus=5.2.5
Tenable Nessus=5.2.6
Tenable Nessus=5.2.7
Tenable Web UI<=2.3.4
Event History
Jul 23, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4980?
CVE-2014-4980 is considered a medium severity vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2014-4980?
To mitigate CVE-2014-4980, upgrade to Nessus version 5.2.8 or newer, or to Tenable Web UI version 2.3.5 or newer.
3
What type of vulnerability is CVE-2014-4980?
CVE-2014-4980 is classified as an information disclosure vulnerability.
4
What software versions are affected by CVE-2014-4980?
Nessus versions 5.2.3 to 5.2.7 and Tenable Web UI versions up to and including 2.3.4 are affected by CVE-2014-4980.
5
Can CVE-2014-4980 be exploited remotely?
Yes, CVE-2014-4980 can be exploited by remote attackers through the token parameter.