CVE-2022-28291
Insufficiently Protected Credentials: An authenticated user with debug privileges can retrieve stored Nessus policy credentials from the “nessusd” process in cleartext via process dumping. The affected products are all versions of Nessus Essentials and Professional. The vulnerability allows an attacker to access credentials stored in Nessus scanners, potentially compromising its customers’ network of assets.
- Affected products
- Nessus, Nessus Essentials, Nessus Professional
- Tenable Nessus
- All versions
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.7% (48th percentile)
- Weakness
- CWE-522
- NVD status
- Modified
- Published
- 2022-10-17
CVE-2022-28291 at NVD
No indexed exploits for CVE-2022-28291 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-28291 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.