CVE-2024-2390: Tenable Nessus

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

As a part of Tenable’s vulnerability disclosure program, a vulnerability in a Nessus plugin was identified and reported. This vulnerability could allow a malicious actor with sufficient permissions on a scan target to place a binary in a specific filesystem location, and abuse the impacted plugin in order to escalate privileges.

Affected products

Published 2024-03-18. Last modified 2026-06-17.