#VU64483 Input validation error in Tenable Nessus - CVE-2022-32974
Published: June 17, 2022
Tenable Nessus
Tenable Network Security
Description
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied input when processing audit files. A remote user can read arbitrary files from the underlying operating system of the scanner using a custom crafted compliance audit file without providing any valid SSH credentials.