Impact
The CVE describes a SQL injection vulnerability that exists when Nessus processes a scan result file imported by a privileged user. By crafting a file containing malicious SQL statements, an attacker can exploit the import routine and inject arbitrary queries into the scan results database. The injected statements may read or exfiltrate sensitive scan-result data, compromising confidentiality of stored findings.
Affected Systems
The vulnerability affects Tenable’s Nessus vulnerability scanner. Any installation of Nessus that allows privileged users to import scan result files via the web interface or other import mechanisms is susceptible. No specific product versions are listed, so all current and earlier releases that retain the same import functionality are potentially affected until a fix is applied.
Risk and Exploitability
The CVSS score of 1.6 indicates a low impact from a severity perspective, and the EPSS score is not available, suggesting limited known exploitation activity. Since the vulnerability requires a privileged user to upload a crafted file, the attack vector is limited and requires social engineering or compromise of legitimate scanner credentials. The vulnerability is not listed in CISA’s KEV catalog, so no publicly known exploits are present. Nonetheless, the risk exists especially in environments where scan result imports are routinely performed by admins who could be tricked.
OpenCVE Enrichment