CVE-2017-7199: High severity Tenable Nessus vulnerability
Published Mar 23, 2017
·Updated
Nessus 6.6.2 - 6.10.3 contains a flaw related to insecure permissions that may allow a local attacker to escalate privileges when the software is running in Agent Mode. Version 6.10.4 fixes this issue.
Affected Software
12 affected components
Tenable Nessus=6.6.2
Tenable Nessus=6.7
Tenable Nessus=6.8.0
Tenable Nessus=6.8.1
Tenable Nessus=6.9.0
Tenable Nessus=6.9.1
Tenable Nessus=6.9.2
Tenable Nessus=6.9.3
Tenable Nessus=6.10.0
Tenable Nessus=6.10.1
Tenable Nessus=6.10.2
Tenable Nessus=6.10.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nessusto a version that resolves this vulnerability.Fixed in 6.10.4
Event History
Mar 23, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7199?
CVE-2017-7199 has a medium severity as it allows local attackers to escalate privileges in Nessus.
2
How do I fix CVE-2017-7199?
To fix CVE-2017-7199, upgrade Nessus to version 6.10.4 or later.
3
Which versions of Nessus are affected by CVE-2017-7199?
Nessus versions 6.6.2 through 6.10.3 are affected by CVE-2017-7199.
4
What type of vulnerability is CVE-2017-7199?
CVE-2017-7199 is a vulnerability related to insecure permissions.
5
Can the CVE-2017-7199 vulnerability be exploited remotely?
No, CVE-2017-7199 can only be exploited by local attackers when the software is running in Agent Mode.