First published: Tue Jun 21 2022(Updated: )
An authenticated attacker could read arbitrary files from the underlying operating system of the scanner using a custom crafted compliance audit file without providing any valid SSH credentials.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tenable Nessus | <10.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32974 is a vulnerability that allows an authenticated attacker to read arbitrary files from the underlying operating system of the scanner using a custom crafted compliance audit file without providing any valid SSH credentials.
CVE-2022-32974 has a severity value of 6.5, which is classified as medium.
Tenable Nessus version up to 10.2.0 is affected by CVE-2022-32974.
An attacker can exploit CVE-2022-32974 by using a custom crafted compliance audit file without providing valid SSH credentials to read arbitrary files from the underlying operating system of the scanner.
Yes, it is recommended to update Tenable Nessus to a version beyond 10.2.0 to mitigate CVE-2022-32974.