CVE-2024-9158: XSS
Published Sep 30, 2024
·Updated
A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI.
Affected Software
1 affected component
Tenable Nessus Network Monitor<6.5.0
Remediation
Information
Tenable has released Nessus Network Monitor 6.5.0 to address these issues. The installation files can be obtained from the Tenable Downloads Portal ( https://www.tenable.com/downloads/nessus-network-monitor https://www.tenable.com/downloads/nessus-network-monitor ).
Event History
Sep 30, 2024
CVE Published
via MITRE·04:24 PM
Data Sourced
via MITRE·04:24 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-9158?
CVE-2024-9158 is classified as a medium-severity vulnerability that allows for stored cross-site scripting.
2
How do I fix CVE-2024-9158?
To remediate CVE-2024-9158, upgrade to the latest version of Tenable Nessus Network Monitor that addresses this vulnerability.
3
Who is affected by CVE-2024-9158?
CVE-2024-9158 affects authenticated users of Tenable Nessus Network Monitor versions prior to 6.5.0.
4
What type of attack does CVE-2024-9158 enable?
CVE-2024-9158 enables a local privileged authenticated attacker to inject arbitrary code through the Nessus Network Monitor UI.
5
When was CVE-2024-9158 disclosed?
CVE-2024-9158 was disclosed in 2024 as a security vulnerability in Tenable Nessus Network Monitor.