CVE-2017-11506

MEDIUM

Description

When linking a Nessus scanner or agent to Tenable.io or other manager, Nessus 6.x before 6.11 does not verify the manager's TLS certificate when making the initial outgoing connection. This could allow man-in-the-middle attacks.

References

http://www.securitytracker.com/id/1039141

https://www.tenable.com/security/tns-2017-11

Details

Source: MITRE

Published: 2017-08-09

Updated: 2017-08-24

Type: CWE-295

Risk Information

CVSS v2.0

Base Score: 5.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Impact Score: 4.9

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3.0

Base Score: 7.4

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Impact Score: 5.2

Exploitability Score: 2.2

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:tenable:nessus:6.0.0:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.0.1:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.0.2:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.1.0:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.1.1:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.1.2:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.2.0:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.2.1:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.3.0:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.3.1:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.3.2:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.3.3:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.3.4:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.3.5:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.3.6:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.3.7:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.4.0:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.4.1:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.4.2:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.4.3:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.5.0:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.5.1:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.5.2:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.5.3:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.5.4:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.5.5:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.5.6:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.6.0:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.6.1:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.6.2:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.7.0:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.8.0:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.8.1:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.9.0:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.9.1:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.9.2:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.9.3:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.10.0:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.10.1:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.10.2:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.10.3:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.10.4:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.10.5:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.10.6:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.10.7:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.10.8:*:*:*:*:*:*:*

cpe:2.3:a:tenable:nessus:6.10.9:*:*:*:*:*:*:*

Tenable Plugins

View all (1 total)

IDNameProductFamilySeverity
102274Tenable Nessus Agent 6.x < 6.11 MITM Vulnerability During Linking (TNS-2017-11)NessusMisc.
medium