Vulnerabilidades em Tenable

81 resultados
Análise Vexday

Com 73 CVEs catalogadas e nenhuma confirmada em exploração ativa pelo CISA KEV, o perfil de risco da Tenable situa-se abaixo da média geral do catálogo, que registra 0,45% de taxa de exploração. A ausência de vulnerabilidades críticas e de novas ocorrências nos últimos 90 dias reforça um cenário de baixa pressão imediata, embora duas CVEs com prova de conceito pública mereçam atenção contínua por reduzirem a barreira técnica para tentativas de exploração. O tipo de falha mais recorrente é CWE-269 (gerenciamento impróprio de privilégios), um padrão que frequentemente serve de vetor para escalonamento de acesso em ambientes corporativos. A CVE mais relevante no momento, CVE-2019-3921, apresenta EPSS de 0,1789, indicando probabilidade não desprezível de exploração e justificando priorização nas rotinas de patching, especialmente em instalações que ainda não aplicaram as correções disponíveis.

CVE-2018-15695ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file system due to a pathEPSS 1.0%CVE-2023-6062MEDIUMArbitrary File WriteEPSS 1.0%CVE-2017-11508SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sEPSS 1.0%CVE-2018-15698ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on the file system when providing EPSS 1.0%CVE-2018-15697ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on a share by providing the full pEPSS 0.8%CVE-2018-15696ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts via user.cgi.EPSS 0.8%CVE-2023-6178MEDIUM An arbitrary file write vulnerability exists where an authenticated attacker with privileges on the managing application could alter NessusEPSS 0.8%CVE-2018-1148In Nessus before 7.1.0, Session Fixation exists due to insufficient session management within the application. An authenticated attacker couEPSS 0.8%CVE-2023-3252MEDIUMArbitrary File WriteEPSS 0.8%CVE-2018-15699ASUSTOR Data Master 3.1.5 and below makes an HTTP request for a configuration file that is vulnerable to XSS. A man in the middle can take aEPSS 0.8%CVE-2024-0971MEDIUM A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter scan DB content. EPSS 0.8%CVE-2018-1155In SecurityCenter versions prior to 5.7.0, a cross-site scripting (XSS) issue could allow an authenticated attacker to inject JavaScript codEPSS 0.8%CVE-2018-1142Tenable Appliance versions 4.6.1 and earlier have been found to contain a single XSS vulnerability. Utilizing a specially crafted request, aEPSS 0.6%CVE-2023-3251MEDIUMPass-back vulnerability in NessusEPSS 0.6%CVE-2026-13007HIGHInsecure Public Caching on REST API Endpoints in Tenable Identity ExposureEPSS 0.6%CVE-2017-11506When linking a Nessus scanner or agent to Tenable.io or other manager, Nessus 6.x before 6.11 does not verify the manager's TLS certificate EPSS 0.6%CVE-2024-0955MEDIUMStored XSS vulnerabilityEPSS 0.6%CVE-2026-15265CRITICALTenable Agent Path Traversal Leading to Remote Code ExecutionEPSS 0.6%CVE-2023-3253MEDIUMImproper authorization in NessusEPSS 0.5%CVE-2018-1153Burp Suite Community Edition 1.7.32 and 1.7.33 fail to validate the server certificate in a couple of HTTPS requests which allows a man in tEPSS 0.5%