Tenable Security Updates – 19 November 2023

Tenable has released security updates to fix two vulnerabilities across multiple Tenable Nessus versions.

The addressed vulnerabilities could allow the remote attacker with administrator privileges to overwrite arbitrary files on the remote host, which could lead to a denial of service condition.

Sample of the addressed vulnerabilities:

Tenable Nessus Denial of Service Vulnerability (CVE-2023-6062):

  • CVSS: 6.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Consequences: Denial of Service

Affected products:

  • Nessus Agent 10.4.3 and earlier.
  • Nessus 10.6.2 and earlier.
  • Nessus 10.5.6 and earlier.
Vulnerabilities
  • CVE-2023-6062
  • CVE-2023-6178
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Tenable Security Updates

References