Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.114194
Category:General
Title:Tenable Nessus Network Monitor < 6.3.1 Multiple Vulnerabilities (TNS-2023-43)
Summary:Tenable Nessus Network Monitor is prone to multiple; vulnerabilities.
Description:Summary:
Tenable Nessus Network Monitor is prone to multiple
vulnerabilities.

Vulnerability Insight:
Several of the third-party components (HandlebarsJS, OpenSSL,
and jquery-file-upload) were found to contain vulnerabilities, and updated versions have been made
available by the providers.

Out of caution and in line with best practice, Tenable has opted to upgrade these components to
address the potential impact of the issues. Nessus Network Monitor 6.3.1 updates HandlebarsJS to
version 4.7.8, OpenSSL to version 3.0.12, and jquery-file-upload to version 10.8.0.

Affected Software/OS:
Tenable Nessus Network Monitor prior to version 6.3.1.

Solution:
Update to version 6.3.1 or later.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-9206
BugTraq ID: 105679
http://www.securityfocus.com/bid/105679
BugTraq ID: 106629
http://www.securityfocus.com/bid/106629
https://www.exploit-db.com/exploits/45790/
https://www.exploit-db.com/exploits/46182/
http://www.vapidlabs.com/advisory.php?v=204
https://wpvulndb.com/vulnerabilities/9136
Common Vulnerability Exposure (CVE) ID: CVE-2021-23369
https://github.com/handlebars-lang/handlebars.js/commit/b6d3de7123eebba603e321f04afdbae608e8fea8
https://github.com/handlebars-lang/handlebars.js/commit/f0589701698268578199be25285b2ebea1c1e427
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074950
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074951
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1074952
https://snyk.io/vuln/SNYK-JS-HANDLEBARS-1056767
Common Vulnerability Exposure (CVE) ID: CVE-2021-23383
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1279031
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1279032
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1279030
https://snyk.io/vuln/SNYK-JS-HANDLEBARS-1279029
Common Vulnerability Exposure (CVE) ID: CVE-2023-5363
Debian Security Information: DSA-5532 (Google Search)
https://www.debian.org/security/2023/dsa-5532
3.0.12 git commit
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=0df40630850fb2740e6be6890bb905d3fc623b2d
3.1.4 git commit
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=5f69f5c65e483928c4b28ed16af6e5742929f1ee
OpenSSL Advisory
https://www.openssl.org/news/secadv/20231024.txt
http://www.openwall.com/lists/oss-security/2023/10/24/1
CopyrightCopyright (C) 2023 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.