Vulnerabilidades en tenable
81 resultadosAnálisis Vexday
Tenable apresenta perfil de risco elevado com 8 vulnerabilidades registradas, das quais 7 foram publicadas nos últimos 90 dias, indicando descobertas recentes em seu portfólio. Embora nenhuma esteja sob exploração ativa comprovada (KEV), 3 são classificadas como críticas, com prevalência de falhas de requisição sem validação (CWE-918) que expõem a sistemas a riscos de acesso não autorizado e exfiltração de dados. A concentração de publicações recentes demanda monitoramento contínuo e priorização de patches críticos.
CVE-2018-15695—ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file system due to a pathEPSS 1.0%CVE-2023-6062MEDIUMArbitrary File WriteEPSS 1.0%CVE-2017-11508—SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sEPSS 1.0%CVE-2018-15698—ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on the file system when providing EPSS 1.0%CVE-2018-15697—ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to read any file on a share by providing the full pEPSS 0.8%CVE-2018-15696—ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts via user.cgi.EPSS 0.8%CVE-2023-6178MEDIUM
An arbitrary file write vulnerability exists where an authenticated attacker with privileges on the managing application could alter NessusEPSS 0.8%CVE-2018-1148—In Nessus before 7.1.0, Session Fixation exists due to insufficient session management within the application. An authenticated attacker couEPSS 0.8%CVE-2018-15699—ASUSTOR Data Master 3.1.5 and below makes an HTTP request for a configuration file that is vulnerable to XSS. A man in the middle can take aEPSS 0.8%CVE-2024-0971MEDIUM
A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter scan DB content.
EPSS 0.8%CVE-2018-1155—In SecurityCenter versions prior to 5.7.0, a cross-site scripting (XSS) issue could allow an authenticated attacker to inject JavaScript codEPSS 0.8%CVE-2018-1142—Tenable Appliance versions 4.6.1 and earlier have been found to contain a single XSS vulnerability. Utilizing a specially crafted request, aEPSS 0.6%CVE-2026-13007HIGHInsecure Public Caching on REST API Endpoints in Tenable Identity ExposureEPSS 0.6%CVE-2023-3252MEDIUMArbitrary File WriteEPSS 0.6%CVE-2017-11506—When linking a Nessus scanner or agent to Tenable.io or other manager, Nessus 6.x before 6.11 does not verify the manager's TLS certificate EPSS 0.6%CVE-2024-0955MEDIUMStored XSS vulnerabilityEPSS 0.6%CVE-2026-15265CRITICALTenable Agent Path Traversal Leading to Remote Code ExecutionEPSS 0.6%CVE-2018-1153—Burp Suite Community Edition 1.7.32 and 1.7.33 fail to validate the server certificate in a couple of HTTPS requests which allows a man in tEPSS 0.5%CVE-2026-47356HIGHTerrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POEPSS 0.5%CVE-2018-1154—In SecurityCenter versions prior to 5.7.0, a username enumeration issue could allow an unauthenticated attacker to automate the discovery ofEPSS 0.5%