Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Tenable has released Nessus 10.8.4 to address these issues. The installation files can be obtained from the Tenable Downloads Portal: https://www.tenable.com/downloads/nessus https://www.tenable.com/downloads/nessus
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-11904 | In Nessus versions prior to 10.8.4, a non-authenticated attacker could alter Nessus logging entries by manipulating http requests to the application. |
| Link | Providers |
|---|---|
| https://www.tenable.com/security/tns-2025-05 |
|
Fri, 18 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 18 Apr 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Nessus versions prior to 10.8.4, a non-authenticated attacker could alter Nessus logging entries by manipulating http requests to the application. | |
| Title | Log Poisoning in Nessus | |
| Weaknesses | CWE-117 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2025-04-18T19:40:24.201Z
Reserved: 2025-04-15T21:50:46.276Z
Link: CVE-2025-36625
Updated: 2025-04-18T19:40:09.629Z
Status : Deferred
Published: 2025-04-18T20:15:16.807
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-36625
No data.
OpenCVE Enrichment
Updated: 2025-07-12T16:01:42Z
EUVD