← Vulnerability feed

Vulnerability record · CVE-2024-9158 · published 30 September 2024

CVE-2024-9158: Tenable nessus network monitor cross-site scripting vulnerability

Tenable · Nessus Network Monitor

A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI.

4.6 CVSS 3.1 Medium EPSS 0.32% · top 77.4% CWE-79 · Cross-site scripting
4.6CVSS 3.1 base score
0.32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local attacker could inject arbitrary code into the NNM UI via the local CLI.

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-9158 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-3711OpenSSL SM2 decryption buffer overflowOpenSSL's SM2 decryption code miscalculates the output buffer size needed by EVP_PKEY_decrypt(), so the first sizing call can return a value smaller …EPSS 88%analysed8.8CVE-2023-5622Tenable nessus network monitor improper privilege management vulnerabilityUnder certain conditions, Nessus Network Monitor could allow a low privileged user to escalate privileges to NT AUTHORITY\SYSTEM on Windows hosts by …EPSS 0.47%7.8CVE-2025-24917Tenable nessus network monitor improper access control vulnerabilityIn Tenable Network Monitor versions prior to 6.5.1 on a Windows host, it was found that a non-administrative user could stage files in a local direct…EPSS 0.16%7.8CVE-2025-24916Tenable nessus network monitor improper access control vulnerabilityWhen installing Tenable Network Monitor to a non-default location on a Windows host, Tenable Network Monitor versions prior to 6.5.1 did not enforce …EPSS 0.15%7.8CVE-2023-5623Tenable nessus network monitor code injection vulnerabilityNNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary code with SYSTEM privileges w…EPSS 0.15%7.8CVE-2020-5794Tenable nessus network monitor vulnerabilityA vulnerability in Nessus Network Monitor versions 5.11.0, 5.11.1, and 5.12.0 for Windows could allow an authenticated local attacker to execute arbi…EPSS 0.37%7.5CVE-2021-23840OpenSSL EVP cipher update integer overflow causes negative output lengthCalls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate can overflow the output length argument when the input length approaches the platf…EPSS 51%analysed7.4CVE-2021-3712OpenSSL ASN.1 string printing out-of-bounds readOpenSSL functions that print ASN.1 data assume ASN1_STRING buffers are NUL terminated, but applications can construct valid ASN1_STRING structures wi…EPSS 50%analysed

Source: NIST National Vulnerability Database (record CVE-2024-9158), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.