Tenable Security Update 01 February 2023

Tenable has released a security update to fix a critical vulnerability in multiple products.

The mentioned vulnerability could allow the authenticated remote attacker to escalate privileges by modifying environment variables and abusing the impacted plugin on the affected system.

Tenable.io, Tenable.sc, and Nessus Privilege Escalation (CVE-2023-0524):

  • CVSS: 9.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Consequences: Gain Privilege

Affected Products:

  • Tenable Nessus.
  • Tenable.io.
  • Tenable.sc
Vulnerabilities
  • CVE-2023-0524
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Tenable Security Advisory

References