CVE-2017-11506: High severity nessus vulnerability
When linking a Nessus scanner or agent to Tenable.io or other manager, Nessus 6.x before 6.11 does not verify the manager's TLS certificate when making the initial outgoing connection. This could allow man-in-the-middle attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11506?
CVE-2017-11506 is rated as medium severity due to the potential for man-in-the-middle attacks.
How do I fix CVE-2017-11506?
To fix CVE-2017-11506, update your Nessus installation to version 6.11 or later.
Which versions of Nessus are affected by CVE-2017-11506?
Versions of Nessus prior to 6.11, specifically 6.0.0 through 6.10.9, are affected by CVE-2017-11506.
What type of attacks can CVE-2017-11506 allow?
CVE-2017-11506 can allow attackers to perform man-in-the-middle attacks due to the lack of TLS certificate verification.
Is there a workaround for CVE-2017-11506?
The recommended solution for CVE-2017-11506 is to upgrade to the latest version of Nessus; no temporary workaround is suggested.