Input validation error in Tenable Nessus - CVE-2022-32974
Published: June 17, 2022
Vulnerability details
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied input when processing audit files. A remote user can read arbitrary files from the underlying operating system of the scanner using a custom crafted compliance audit file without providing any valid SSH credentials.
Affected software
Nessus Agent
How to mitigate CVE-2022-32974
Nessus Agent - addressed in versions 8.3.4, 10.1.4