CVE-2024-0955: Stored XSS vulnerability
A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus proxy settings, which could lead to the execution of remote arbitrary scripts.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0955?
CVE-2024-0955 is considered a critical severity vulnerability due to the potential for remote code execution.
How does CVE-2024-0955 affect Tenable Nessus?
CVE-2024-0955 affects Tenable Nessus by allowing authenticated, remote attackers with administrator privileges to execute remote arbitrary scripts.
What versions of Nessus are affected by CVE-2024-0955?
CVE-2024-0955 affects Tenable Nessus versions prior to 10.7.0 exclusively.
How can I remediate CVE-2024-0955?
To remediate CVE-2024-0955, upgrade Tenable Nessus to version 10.7.0 or later.
Who can exploit CVE-2024-0955?
Only authenticated remote attackers with administrator privileges on the Nessus application can exploit CVE-2024-0955.