CVE-2018-1148: Tenable Nessus

Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.

In Nessus before 7.1.0, Session Fixation exists due to insufficient session management within the application. An authenticated attacker could maintain system access due to session fixation after a user password change.

Affected products

  • Tenable Nessus: before 7.1.0 (fixed in 7.1.0)

Published 2018-05-18. Last modified 2026-06-17.