Vulnerabilities > Tenable > Nessus > High

DATE CVE VULNERABILITY TITLE RISK
2017-08-09 CVE-2017-11506 Improper Certificate Validation vulnerability in Tenable Nessus
When linking a Nessus scanner or agent to Tenable.io or other manager, Nessus 6.x before 6.11 does not verify the manager's TLS certificate when making the initial outgoing connection.
network
high complexity
tenable CWE-295
7.4
2017-04-19 CVE-2017-7850 Incorrect Permission Assignment for Critical Resource vulnerability in Tenable Nessus
Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local privilege escalation issue due to insecure permissions when running in Agent Mode.
local
low complexity
tenable CWE-732
7.8
2017-03-23 CVE-2017-7199 Incorrect Permission Assignment for Critical Resource vulnerability in Tenable Nessus
Nessus 6.6.2 - 6.10.3 contains a flaw related to insecure permissions that may allow a local attacker to escalate privileges when the software is running in Agent Mode.
local
low complexity
tenable CWE-732
7.8
2017-03-08 CVE-2017-6543 Unspecified vulnerability in Tenable Nessus
Tenable Nessus before 6.10.2 (as used alone or in Tenable Appliance before 4.5.0) was found to contain a flaw that allowed a remote, authenticated attacker to upload a crafted file that could be written to anywhere on the system.
local
low complexity
tenable
7.3