Session Fixation Vulnerability in Nessus by Tenable
CVE-2018-1148

6.5MEDIUM

Key Information:

Vendor

Tenable

Vendor
CVE Published:
18 May 2018

What is CVE-2018-1148?

In Nessus versions prior to 7.1.0, a session fixation vulnerability exists due to inadequate session management. This flaw allows an authenticated attacker to maintain access to a user's session even after the user changes their password, thereby compromising the security of user accounts. Organizations using affected versions of Nessus should upgrade to at least version 7.1.0 to mitigate this risk.

Affected Version(s)

Tenable Nessus All versions prior to 7.1.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.