CVE-2022-3499: Medium severity nessus vulnerability
Published Oct 31, 2022
·Updated
An authenticated attacker could utilize the identical agent and cluster node linking keys to potentially allow for a scenario where unauthorized disclosure of agent logs and data is present.
Affected Software
1 affected component
Tenable Nessus<10.4.0
Event History
Oct 31, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-3499?
CVE-2022-3499 is a vulnerability that allows an authenticated attacker to potentially disclose unauthorized agent logs and data.
2
What is the severity of CVE-2022-3499?
CVE-2022-3499 has a severity rating of 6.5 (medium).
3
What software is affected by CVE-2022-3499?
Tenable Nessus version up to 10.4.0 is affected by CVE-2022-3499.
4
How can an attacker exploit CVE-2022-3499?
An authenticated attacker can exploit CVE-2022-3499 by utilizing identical agent and cluster node linking keys.
5
How can I protect against CVE-2022-3499?
To protect against CVE-2022-3499, apply the necessary patches or updates provided by Tenable Nessus.