Zum Inhalt springen

Nessus Updates & Release Notes

4 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Nessus, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nessus von Tenable

Tenable Nessus 10.12.5: Signaturpflicht für Plugin-Updates, Sicherheitsfixes

Tenable Nessus 10.12.5 verlangt für manuelle Plugin-Updates in Tenable Nessus und Tenable Nessus Manager nun die Signaturdatei und behebt mehrere Sicherheitslücken, darunter Speicherfehler im Plugin-Loader, fehlende Signaturprüfung beim Legacy-Update-Kanal und eine SQL-Injection beim Import von Scan-Policies.

ClosedChanged Functionality and Performance Enhancements

The following changes are included in Tenable Nessus 10.12.5:

  • Manual plugin updates for both Tenable Nessus and Tenable Nessus Manager now require the signature file to process plugin updates. This change does not impact Tenable Security Center plugin updates, Tenable Nessus Manager's agent plugin updates, or Tenable Nessus application updates.

ClosedSecurity Updates

The following are security updates included in Tenable Nessus 10.12.5:

  • Fixed multiple memory-safety flaws in the plugin file loader.

  • Fixed an out-of-bounds memory access in the plugin execution engine's logic.

  • Fixed a denial-of-service condition where a crafted plugin file could trigger a crash-restart loop.

  • Fixed an out-of-bounds read in the plugin file parser that could expose internal scanner memory in diagnostic output.

  • Fixed a double-free memory corruption that could be triggered by a crafted plugin.

  • Fixed a vulnerability where plugin archives pushed through the legacy update channel were installed without signature verification. Uploaded plugin archives are now required to carry a valid Tenable signature before they are extracted or loaded.

  • Fixed a SQL injection vulnerability in the scan policy import functionality. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nessus von Tenable

Tenable Nessus 10.12.4: Korrekturen bei Kerberos, Timeouts und PostgreSQL

Tenable Nessus 10.12.4 behebt Fehler, durch die Kerberos-Plugins keine Host-FQDNs abrufen konnten, Tenable Security Center bei vielen Agent-Berichten in Timeouts lief und bei PostgreSQL-Zertifikatsauthentifizierung nur das erste Zertifikat der Kette geladen wurde.

ClosedBug Fixes

Bug Fix

Defect ID

Fixed an issue that blocked Kerberos plugins from retrieving host FQDNs, causing plugin authentication failures.

02502988, 02506935

Fixed an issue that caused Tenable Security Center to suffer timeout-related errors while processing many Tenable Nessus Manager agent reports.

02492101

Fixed an issue where only the first (leaf) certificate was loaded when a plugin performed PostgreSQL client authentication using a certificate chain.

02502389

ClosedUpgrade Notes

  • Tenable One Vulnerability Management FedRAMP environments support Tenable Nessus scanners versions 10.5.0 and later.

  • If you are connecting to Tenable One Vulnerability Management through Tenable Nessus scanners, Tenable Agents, Tenable One Web App Scanning scanners, or Tenable Network Monitors (NNM) located in mainland China, you must connect through sensor.cloud.tenablecloud.cn instead of sensor.cloud.tenable.com.

  • You can upgrade to the latest version of Tenable Nessus from any previously supported version.

  • If your upgrade path skips versions of Tenable Nessus, Tenable recommends reviewing the release notes for all skipped versions to learn about new features and bug fixes. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nessus von Tenable

Tenable Nessus 10.12.3: SSL-Verbindung zu Tenable One nach Upgrade behoben

Tenable Nessus 10.12.3 behebt ein Problem, bei dem einige Scanner nach einem Upgrade keine SSL-Verbindung zu Tenable One Vulnerability Management aufbauen konnten und dadurch offline erschienen und keine Plugin-Updates erhielten.

ClosedBug Fixes

Bug Fix

Defect ID

Resolved an issue where some Tenable Nessus scanners could not establish SSL connections to Tenable One Vulnerability Management after an upgrade. This issue caused the scanners to appear offline and stopped plugin updates.

02526315, 02523672, 02525991, 02526826, 02525419, 02527133, 02524407

ClosedUpgrade Notes

  • Tenable One Vulnerability Management FedRAMP environments support Tenable Nessus scanners versions 10.5.0 and later.

  • If you are connecting to Tenable One Vulnerability Management through Tenable Nessus scanners, Tenable Agents, Tenable One Web App Scanning scanners, or Tenable Network Monitors (NNM) located in mainland China, you must connect through sensor.cloud.tenablecloud.cn instead of sensor.cloud.tenable.com.

  • You can upgrade to the latest version of Tenable Nessus from any previously supported version.

  • If your upgrade path skips versions of Tenable Nessus, Tenable recommends reviewing the release notes for all skipped versions to learn about new features and bug fixes.

  • If you want your scanners to update to the newest version before the GA date automatically, set your Tenable Nessus Update Plan to Opt in to Early Access releases. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Nessus von Tenable

Tenable Nessus 10.12.2: Korrekturen bei Agents, Cluster-Scans und TLS 1.3

Tenable Nessus 10.12.2 behebt Fehler bei der angezeigten Plugin-Set-Version verknüpfter Agents (erfordert Tenable Agent 11.2.0 oder neuer), bei unvollständigen Cluster-Agent-Scans, beim sofortigen Auslösen von host_time_minutes sowie bei der Wirkung von ssl_cipher_list auf TLS-1.3-Cipher-Suites.

ClosedBug Fixes

Bug Fix

Defect ID

Fixed an issue that caused Tenable Nessus Manager to report the previously installed version of the plugin set on a linked agent.

This fix also requires Tenable Agent version 11.2.0 or later.

02317032, 02304552, 02503048, 02507161

Fixed an issue where cluster-based agent scans started but did not complete. For database records of these incomplete scans, the cleanup process now correctly considers their associated files as "in use" and preserves them.

02430539

Fixed an issue where the host_time_minutes parameter triggered immediately for a host, which caused the scan for that host to abort.

02441109

Fixed an issue where the ssl_cipher_list preference did not control the TLS 1.3 cipher suites.

02510984

ClosedUpgrade Notes

  • Tenable One Vulnerability Management FedRAMP environments support Tenable Nessus scanners versions 10.5.0 and later.

  • If you are connecting to Tenable One Vulnerability Management through Tenable Nessus scanners, Tenable Agents, Tenable One Web App Scanning scanners, or Tenable Network Monitors (NNM) located in mainland China, you must connect through sensor.cloud.tenablecloud.cn instead of sensor.cloud.tenable.com. …

Originalquelle(öffnet in neuem Tab)Problem melden