SB2022062020 - Multiple vulnerabilities in Nessus Agent
Published: June 20, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) OS Command Injection (CVE-ID: CVE-2022-32973)
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation. A remote user can create an audit file that bypasses PowerShell cmdlet checks and executes commands with administrator privileges.
2) Input validation error (CVE-ID: CVE-2022-32974)
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied input when processing audit files. A remote user can read arbitrary files from the underlying operating system of the scanner using a custom crafted compliance audit file without providing any valid SSH credentials.
Remediation
Install update from vendor's website.