CVE-2024-0971: SQL Injection
Published Feb 6, 2024
·Updated
A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter scan DB content.
Affected Software
1 affected component
Tenable Nessus<10.7.0
Remediation
Information
Tenable has released Nessus 10.7.0 to address these issues. The installation files can be obtained from the Tenable Downloads Portal ( https://www.tenable.com/downloads/nessus https://www.tenable.com/downloads/nessus ).
Event History
Feb 6, 2024
CVE Published
via MITRE·11:38 PM
Data Sourced
via MITRE·11:38 PM
RemedyDescriptionSeverityWeakness
Apr 22, 56092
Event
via NVD·11:37 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-0971?
CVE-2024-0971 is classified as a SQL injection vulnerability which can potentially lead to unauthorized data manipulation.
2
How do I fix CVE-2024-0971?
To remediate CVE-2024-0971, it is recommended to upgrade Tenable Nessus to version 10.7.0 or later.
3
Who is affected by CVE-2024-0971?
CVE-2024-0971 affects authenticated users of Tenable Nessus versions below 10.7.0.
4
What type of attack does CVE-2024-0971 facilitate?
CVE-2024-0971 facilitates SQL injection attacks allowing low-privileged authenticated attackers to alter scan database content.
5
Is there a workaround for CVE-2024-0971?
Currently, there are no known workarounds for CVE-2024-0971 other than applying the recommended software update.