CVE-2022-4313
Tenable Nessus vulnerability analysis and mitigation

Overview

A critical vulnerability (CVE-2022-4313) was discovered in Tenable products that affects authenticated users with Scan Policy Configuration roles. The vulnerability was reported on August 25, 2022, and confirmed on September 1, 2022. The affected products include Tenable.sc, Tenable.io, and Nessus (Tenable Advisory).

Technical details

The vulnerability has a CVSSv3 Base/Temporal Score of 9.1/8.2 with the vector AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C. The issue exists in built-in audits that are selected through product interfaces, but does not affect custom audits uploaded by customers. Through modifying scan variables, an authenticated user with Scan Policy Configuration roles could manipulate audit policy variables (Tenable Advisory).

Impact

The vulnerability allows authenticated users to execute arbitrary commands on credentialed scan targets, potentially leading to complete system compromise. This could result in unauthorized access to sensitive information and system control (Tenable Advisory).

Mitigation and workarounds

Tenable has released updated compliance plugins and audit files that validate customer-entered values against defined variable types. The fixes were distributed via plugin feed 202212081952 or later. Tenable.io has been updated with necessary plugins and content. Tenable.sc updates are distributed in the feed and activated with new templates. Nessus users should upgrade to version 10.4.2 or later, or perform a manual update of the audit warehouse (Tenable Advisory).

Additional resources


SourceThis report was generated using AI

Related Tenable Nessus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-3290HIGH8.2
  • Tenable NessusTenable Nessus
  • cpe:2.3:a:tenable:nessus
NoYesMay 17, 2024
CVE-2025-24914HIGH7.8
  • Tenable NessusTenable Nessus
  • cpe:2.3:a:tenable:nessus
NoYesApr 18, 2025
CVE-2025-24915HIGH7.8
  • Tenable NessusTenable Nessus
  • cpe:2.3:a:tenable:nessus
NoYesMar 21, 2025
CVE-2025-36630HIGH7.1
  • Tenable NessusTenable Nessus
  • nessus
NoYesJul 02, 2025
CVE-2025-36625MEDIUM4.3
  • Tenable NessusTenable Nessus
  • cpe:2.3:a:tenable:nessus
NoYesApr 18, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management