QID 376713

QID 376713: Tenable Nessus Multiple Third-Party Vulnerabilities (TNS-2022-05)

Nessus is a proprietary vulnerability scanner.

Affected Versions:
Nessus 10.1.1 and Nessus 8.15.3

QID Detection Logic (Authenticated):
This QID checks for the existence of vulnerable versions of Nessus in registry.

In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    The vendor has issued a fix in Nessus version 10.1.1 and Nessus 8.15.3 Refer to Nessus advisory TNS-2022-05 to address this issue and obtain more information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    TNS-2022-05 URL Logo www.tenable.com/security/tns-2022-05