← Vulnerability feed

Vulnerability record · CVE-2023-2005 · published 26 June 2023

CVE-2023-2005: Tenable nessus uncontrolled search path element vulnerability

Tenable · Nessus

Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nessus: before Plugin Feed ID #202306261202 ; Security Center: before Plugin Feed ID #202306261202 . This vulnerability could allow a malicious actor with sufficient permissions on a scan target to place a binary in a specific filesystem location, and abuse the impacted plugin in order to escalate privileges.

8.8 CVSS 3.1 High EPSS 0.38% · top 70.8% CWE-427 · Uncontrolled search path element
8.8CVSS 3.1 base score
0.38%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
2References
17 Aug 2026Last modified by NVD

Description

Vulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nessus: before Plugin Feed ID #202306261202 ; Security Center: before Plugin Feed ID #202306261202 . This vulnerability could allow a malicious actor with sufficient permissions on a scan target to place a binary in a specific filesystem location, and abuse the impacted plugin in order to escalate privileges.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-2005 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-23852Libexpat project libexpat integer overflow vulnerabilityExpat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.EPSS 4.6%9.8CVE-2022-22822Libexpat project libexpat integer overflow vulnerabilityaddBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.EPSS 4.8%9.8CVE-2022-22823Libexpat project libexpat integer overflow vulnerabilitybuild_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.EPSS 3.4%9.8CVE-2022-22824Libexpat project libexpat integer overflow vulnerabilitydefineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.EPSS 3.4%9.8CVE-2019-11049Php double free vulnerabilityIn PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4…EPSS 4.2%9.4CVE-2026-19681Tenable security center os command injection vulnerabilityAn authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by…EPSS 9.9%9.4CVE-2026-19682Tenable security center os command injection vulnerabilityA command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary co…EPSS 2.8%9.4CVE-2026-19626Tenable security center vulnerabilityA remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user …EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2023-2005), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.