← Vulnerability feed

Vulnerability record · CVE-2023-5624 · published 26 October 2023

CVE-2023-5624: Tenable nessus network monitor improper input validation vulnerability

Tenable · Nessus Network Monitor

Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow an admin user to alter parameters that could potentially allow a blindSQL injection.

7.2 CVSS 3.1 High EPSS 0.48% · top 60.7% CWE-20 · Improper input validation
7.2CVSS 3.1 base score
0.48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Under certain conditions, Nessus Network Monitor was found to not properly enforce input validation. This could allow an admin user to alter parameters that could potentially allow a blindSQL injection.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-5624 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-3711OpenSSL SM2 decryption buffer overflowOpenSSL's SM2 decryption code miscalculates the output buffer size needed by EVP_PKEY_decrypt(), so the first sizing call can return a value smaller …EPSS 88%analysed8.8CVE-2023-5622Tenable nessus network monitor improper privilege management vulnerabilityUnder certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORITY\SYSTEM on Windows hosts by …EPSS 0.47%7.8CVE-2025-24917Tenable nessus network monitor improper access control vulnerabilityIn Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local direct…EPSS 0.16%7.8CVE-2025-24916Tenable nessus network monitor improper access control vulnerabilityWhen installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce …EPSS 0.15%7.8CVE-2023-5623Tenable nessus network monitor code injection vulnerabilityNNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary code with SYSTEM privileges w…EPSS 0.15%7.8CVE-2020-5794Tenable nessus network monitor vulnerabilityA vulnerability in Nessus Network Monitor versions 5.11.0, 5.11.1, and 5.12.0 for Windows could allow an authenticated local attacker to execute arbi…EPSS 0.37%7.5CVE-2021-23840OpenSSL EVP cipher update integer overflow causes negative output lengthCalls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate can overflow the output length argument when the input length approaches the platf…EPSS 51%analysed7.4CVE-2021-3712OpenSSL ASN.1 string printing out-of-bounds readOpenSSL functions that print ASN.1 data assume ASN1_STRING buffers are NUL terminated, but applications can construct valid ASN1_STRING structures wi…EPSS 50%analysed

Source: NIST National Vulnerability Database (record CVE-2023-5624), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.