Session Fixation Vulnerability in Nessus by Tenable
CVE-2018-1148
6.5MEDIUM
What is CVE-2018-1148?
In Nessus versions prior to 7.1.0, a session fixation vulnerability exists due to inadequate session management. This flaw allows an authenticated attacker to maintain access to a user's session even after the user changes their password, thereby compromising the security of user accounts. Organizations using affected versions of Nessus should upgrade to at least version 7.1.0 to mitigate this risk.
Affected Version(s)
Tenable Nessus All versions prior to 7.1.0