CVE-2023-3252: Arbitrary File Write
Published Aug 29, 2023
·Updated
An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges could alter logging variables to overwrite arbitrary files on the remote host with log data, which could lead to a denial of service condition.
Affected Software
1 affected component
Tenable Nessus<10.6.0
Remediation
Information
Tenable has released Nessus 10.6.0 to address these issues. The installation files can be obtained from the Tenable Downloads Portal ( https://www.tenable.com/downloads/nessus https://www.tenable.com/downloads/nessus ).
Event History
Aug 29, 2023
CVE Published
via MITRE·06:55 PM
Data Sourced
via MITRE·06:55 PM
RemedyDescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-3252.
2
What is the severity of CVE-2023-3252?
The severity of CVE-2023-3252 is medium with a CVSS score of 6.8.
3
How does CVE-2023-3252 affect Tenable Nessus?
CVE-2023-3252 affects Tenable Nessus version up to 10.6.0.
4
What is the impact of CVE-2023-3252?
CVE-2023-3252 can lead to a denial of service condition by allowing an authenticated remote attacker to overwrite arbitrary files on the remote host with log data.
5
How can the arbitrary file write vulnerability in CVE-2023-3252 be fixed?
To fix the arbitrary file write vulnerability in CVE-2023-3252, it is recommended to update Tenable Nessus to a version beyond 10.6.0.