CVE-2023-3253: Improper authorization in Nessus
Published Aug 29, 2023
·Updated
An improper authorization vulnerability exists where an authenticated, low privileged remote attacker could view a list of all the users available in the application.
Affected Software
1 affected component
Tenable Nessus<10.6.0
Remediation
Information
Tenable has released Nessus 10.6.0 to address these issues. The
installation files can be obtained from the Tenable Downloads Portal ( https://www.tenable.com/downloads/nessus https://www.tenable.com/downloads/nessus ).
Event History
Aug 29, 2023
CVE Published
via MITRE·07:08 PM
Data Sourced
via MITRE·07:08 PM
RemedyDescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2023-3253.
2
What is the severity rating of CVE-2023-3253?
CVE-2023-3253 has a severity rating of 4.3, which is considered medium.
3
What is the affected software for CVE-2023-3253?
The affected software for CVE-2023-3253 is Tenable Nessus up to version 10.6.0.
4
What is the impact of CVE-2023-3253?
The impact of CVE-2023-3253 is that an authenticated low privileged remote attacker could view a list of all the users available in the application.
5
How can I fix CVE-2023-3253?
To fix CVE-2023-3253, it is recommended to apply the necessary patches or updates provided by the software vendor.