Home/Product/tenable nessus network monitor
Product

tenable nessus network monitor

14 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-24917
< 6.5.1
In Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage file
7.8HIGH
CVE-2025-24916
< 6.5.1
When installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5
7.0HIGH
CVE-2024-9158
< 6.5.0
A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker cou
8.4HIGH
CVE-2023-5624
< 6.3.0
Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow an admin use
7.2HIGH
CVE-2023-5623
< 6.3.0
NNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary code with
7.0HIGH
CVE-2023-5622
< 6.3.0
Under certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORITY\SYSTEM o
7.1HIGH
CVE-2021-3712
< 6.0.0
ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string dat
7.4HIGH
CVE-2021-3711
<= 5.13.1
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an applic
9.8CRITICAL
CVE-2021-3450
all versions
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not
7.4HIGH
CVE-2021-3449
all versions
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renego
5.9MEDIUM
CVE-2021-23841
all versions
The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and seria
5.9MEDIUM
CVE-2021-23840
all versions
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the
7.5HIGH
CVE-2020-1971
< 5.13.1
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPar
5.9MEDIUM
CVE-2020-5794
all versions
A vulnerability in Nessus Network Monitor versions 5.11.0, 5.11.1, and 5.12.0 for Windows could allow an authenticated local attac
7.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin