CVE-2023-6178

Severity
6.5MEDIUM
EPSS
0.1%
top 73.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 20

Description

An arbitrary file write vulnerability exists where an authenticated attacker with privileges on the managing application could alter Nessus Rules variables to overwrite arbitrary files on the remote host, which could lead to a denial of service condition.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:HExploitability: 2.3 | Impact: 4.0

Affected Packages2 packages

NVDtenable/nessus< 10.4.4
CVEListV5tenable/nessus_agent< 10.4.3

🔴Vulnerability Details

2
CVEList
CVE-2023-6178: An arbitrary file write vulnerability exists where an authenticated attacker with privileges on the managing application could alter Nessus Rules vari2023-11-20
GHSA
GHSA-8hj6-r7xc-4vrv: An arbitrary file write vulnerability exists where an authenticated attacker with privileges on the managing application could alter Nessus Rules vari2023-11-20
CVE-2023-6178 (MEDIUM CVSS 6.5) | An arbitrary file write vulnerabili | cvebase.io