Tenable Nessus
cpe:2.3:a:tenable:nessus:*:*:*:*:*:*:*
- <= 10.8.3
A vulnerability exists in Nessus versions prior to 10.8.4, allowing non-authenticated attackers to modify logging entries by manipulating HTTP requests. This issue arises from improper output neutralization for logs, enabling the alteration of log data.
Exploitation of this vulnerability allows for unauthorized modification of Nessus log entries, potentially leading to misrepresentation of scan results or activity.
Users can upgrade to Nessus version 10.8.4, which addresses this vulnerability. The installation files are available from the Tenable Downloads Portal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.