ZDI-23-1582: Tenable Nessus Link Following Local Privilege Escalation Vulnerability
Published Nov 6, 2023
·Updated
This vulnerability allows local attackers to escalate privileges on affected installations of Tenable Nessus. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.7. The following CVEs are assigned: CVE-2023-5847.
Affected Software
1 affected component
Tenable Nessus
Event History
Nov 6, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-1582?
ZDI-23-1582 has been assigned a CVSS rating of 6, indicating a medium severity level.
2
How do I fix ZDI-23-1582?
To mitigate ZDI-23-1582, ensure that you update Tenable Nessus to the latest version provided by the vendor.
3
What software is affected by ZDI-23-1582?
ZDI-23-1582 affects Tenable Nessus installations.
4
Who can exploit ZDI-23-1582?
Local attackers who can execute low-privileged code on the system can exploit ZDI-23-1582.
5
What type of vulnerability is ZDI-23-1582?
ZDI-23-1582 is a privilege escalation vulnerability.