Vulnerability Description
When linking a Nessus scanner or agent to Tenable.io or other manager, Nessus 6.x before 6.11 does not verify the manager's TLS certificate when making the initial outgoing connection. This could allow man-in-the-middle attacks.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenable | Nessus | 6.0.0 |
Related Weaknesses (CWE)
References
- http://www.securitytracker.com/id/1039141Third Party AdvisoryVDB Entry
- https://www.tenable.com/security/tns-2017-11Vendor Advisory
- http://www.securitytracker.com/id/1039141Third Party AdvisoryVDB Entry
- https://www.tenable.com/security/tns-2017-11Vendor Advisory
FAQ
What is CVE-2017-11506?
CVE-2017-11506 is a vulnerability with a CVSS score of 7.4 (HIGH). When linking a Nessus scanner or agent to Tenable.io or other manager, Nessus 6.x before 6.11 does not verify the manager's TLS certificate when making the initial outgoing connection. This could allo...
How severe is CVE-2017-11506?
CVE-2017-11506 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-11506?
Check the references section above for vendor advisories and patch information. Affected products include: Tenable Nessus.