HIGH
Race Condition
Published May 17, 2024
8.2
HIGHCVSS 3.1
EPSS 0.18%
Description
A race condition vulnerability exists where an authenticated, local attacker on a Windows Nessus host could modify installation parameters at installation time, which could lead to the execution of arbitrary code on the Nessus host
Affected products
-
- Version 0StatusaffectedConstraints<10.7.3
- Version
No data.
-
- Version -StatusaffectedConstraints<=10.7.2
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Tenable has released Nessus 10.7.3 to address these issues. The installation files can be obtained from the Tenable Downloads Portal ( https://www.tenable.com/downloads/nessus ).
Weaknesses (1)
References (2)
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner tenable
Published May 17, 2024
Updated Aug 1, 2024
Reserved Apr 3, 2024
Link CVE-2024-3290
CISA Vulnrichment
Updated May 17, 2024
ENISA EUVD
EUVD-2024-31880 Assigner tenable
Published May 17, 2024
Updated Aug 1, 2024
Exploited since n/a
Link EUVD-2024-31880