Tenable Appliance vulnerabilities
4 known vulnerabilities affecting tenable/appliance.
Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2018-1142MEDIUMCVSS 5.4≤ 4.6.12018-03-28
CVE-2018-1142 [MEDIUM] CWE-79 CVE-2018-1142: Tenable Appliance versions 4.6.1 and earlier have been found to contain a single XSS vulnerability.
Tenable Appliance versions 4.6.1 and earlier have been found to contain a single XSS vulnerability. Utilizing a specially crafted request, an authenticated attacker could potentially execute arbitrary JavaScript code by manipulating certain URL parameters related to offline plugins.
nvd
CVE-2017-8051CRITICALCVSS 9.8PoCv3.4.0v3.5.0+9 more2017-04-21
CVE-2017-8051 [CRITICAL] CWE-78 CVE-2017-8051: Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py s
Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of the tns_appliance_session_user parameter, a remote attacker can inject arbitrary commands.
nvd
CVE-2017-8050HIGHCVSS 7.5≤ 4.4.02017-04-21
CVE-2017-8050 [HIGH] CVE-2017-8050: Tenable Appliance 4.4.0, and possibly prior, contains a flaw in the Web UI that allows for the unaut
Tenable Appliance 4.4.0, and possibly prior, contains a flaw in the Web UI that allows for the unauthorized manipulation of the admin password.
nvd
CVE-2017-6543HIGHCVSS 7.3v4.4.02017-03-08
CVE-2017-6543 [HIGH] CVE-2017-6543: Tenable Nessus before 6.10.2 (as used alone or in Tenable Appliance before 4.5.0) was found to conta
Tenable Nessus before 6.10.2 (as used alone or in Tenable Appliance before 4.5.0) was found to contain a flaw that allowed a remote, authenticated attacker to upload a crafted file that could be written to anywhere on the system. This could be used to subsequently gain elevated privileges on the system (e.g., after a reboot). This issue only affects installatio
nvd