When linking a Nessus scanner or agent to Tenable.io or other manager, Nessus 6.x before 6.11 does not verify the manager's TLS certificate when making the initial outgoing connection. This could allow man-in-the-middle attacks.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://www.tenable.com/security/tns-2017-11 | vendor advisory |
http://www.securitytracker.com/id/1039141 | vdb entry third party advisory |