#VU83307 Arbitrary file upload in Tenable Nessus - CVE-2023-6062 

 

#VU83307 Arbitrary file upload in Tenable Nessus - CVE-2023-6062

Published: November 20, 2023


Vulnerability identifier: #VU83307
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2023-6062
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Tenable Nessus
Software vendor:
Tenable Network Security

Description

The vulnerability allows a remote user to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of file during file upload. A remote user with administrative privileges can alter Nessus Rules variables and overwrite arbitrary files on the remote host, leading to denial of service.


Remediation

Install updates from vendor's website.

External links