CVE-2022-4313: Tenable Nessus
High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.
A vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, that has Scan Policy Configuration roles, could manipulate audit policy variables to execute arbitrary commands on credentialed scan targets.
Affected products
- Tenable Nessus: before 10.4.2 (fixed in 10.4.2)
- Tenable Plugin Feed: before 202212081952 (fixed in 202212081952)
Published 2023-03-15. Last modified 2026-06-17.