CVE-2014-4980: Tenable Nessus

Medium severity, CVSS 5.0. EPSS: 1.7% chance of exploitation in the next 30 days.

The /server/properties resource in Tenable Web UI before 2.3.5 for Nessus 5.2.3 through 5.2.7 allows remote attackers to obtain sensitive information via the token parameter.

Affected products

  • Tenable Nessus: version 5.2.3 only; version 5.2.4 only; version 5.2.5 only; version 5.2.6 only; version 5.2.7 only
  • Tenable Web UI: up to and including 2.3.4

Published 2014-07-23. Last modified 2026-06-17.