CVE-2023-5624: Blind SQL Injection
Published Oct 26, 2023
·Updated
Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow an admin user to alter parameters that could potentially allow a blindSQL injection.
Affected Software
1 affected component
Tenable Nessus Network Monitor<6.3.0
Remediation
Patch Available
Event History
Oct 26, 2023
CVE Published
via MITRE·04:36 PM
Data Sourced
via MITRE·04:36 PM
DescriptionSeverityWeakness
May 24, 57290
Event
via FIRST·01:25 AM
Frequently Asked Questions
1
What is CVE-2023-5624?
CVE-2023-5624 is a vulnerability known as Blind SQL Injection.
2
What is the severity of CVE-2023-5624?
The severity of CVE-2023-5624 is high with a score of 7.2.
3
Which software is affected by CVE-2023-5624?
Tenable Nessus Network Monitor up to version 6.3.0 is affected by CVE-2023-5624.
4
How can an admin user exploit CVE-2023-5624?
An admin user can potentially exploit CVE-2023-5624 by altering parameters and performing a blind SQL injection.
5
Is there a fix available for CVE-2023-5624?
There is no specific fix mentioned in the provided reference, but it is recommended to update to a version beyond 6.3.0 to mitigate the vulnerability.