← Vulnerability feed

Vulnerability record · CVE-2023-0101 · published 20 January 2023

CVE-2023-0101: Tenable nessus improper privilege management vulnerability

Tenable · Nessus

A privilege escalation vulnerability was identified in Nessus versions 8.10.1 through 8.15.8 and 10.0.0 through 10.4.1. An authenticated attacker could potentially execute a specially crafted file to obtain root or NT AUTHORITY / SYSTEM privileges on the Nessus host.

8.8 CVSS 3.1 High EPSS 0.82% · top 44.5% CWE-269 · Improper privilege management
8.8CVSS 3.1 base score
0.82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A privilege escalation vulnerability was identified in Nessus versions 8.10.1 through 8.15.8 and 10.0.0 through 10.4.1. An authenticated attacker could potentially execute a specially crafted file to obtain root or NT AUTHORITY / SYSTEM privileges on the Nessus host.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.tenable.com/security/tns-2023-01 PatchRelease NotesVendor Advisory
https://www.tenable.com/security/tns-2023-02 PatchRelease NotesVendor Advisory
https://www.tenable.com/security/tns-2023-01 PatchRelease NotesVendor Advisory
https://www.tenable.com/security/tns-2023-02 PatchRelease NotesVendor Advisory

Track CVE-2023-0101 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-23852Libexpat project libexpat integer overflow vulnerabilityExpat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.EPSS 4.6%9.8CVE-2022-22822Libexpat project libexpat integer overflow vulnerabilityaddBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.EPSS 4.8%9.8CVE-2022-22823Libexpat project libexpat integer overflow vulnerabilitybuild_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.EPSS 3.4%9.8CVE-2022-22824Libexpat project libexpat integer overflow vulnerabilitydefineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.EPSS 3.4%8.8CVE-2023-2005Tenable nessus uncontrolled search path element vulnerabilityVulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nes…EPSS 0.38%8.8CVE-2022-4313Tenable nessus uncontrolled search path element vulnerabilityA vulnerability was reported where through modifying the scan variables, an authenticated user in Tenable products, that has Scan Policy Configuratio…EPSS 1.2%8.8CVE-2023-0524Tenable nessus improper privilege management vulnerabilityAs part of our Security Development Lifecycle, a potential privilege escalation issue was identified internally. This could allow a malicious actor w…EPSS 0.64%8.8CVE-2022-32973Tenable nessus vulnerabilityAn authenticated attacker could create an audit file that bypasses PowerShell cmdlet checks and executes commands with administrator privileges.EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2023-0101), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.