[R1] Nessus 8.1.1 Fixes Multiple Third-party Vulnerabilities

Related Vulnerabilities: CVE-2018-5407   CVE-2018-0734  

Nessus leverages third-party software to help provide underlying functionality. One third-party component (OpenSSL) was found to contain vulnerabilities, and updated versions have been made available by the providers. Out of caution and in line with good practice, Tenable opted to upgrade the bundled libraries to address the potential impact of these issues in Nessus. Nessus 8.1.1 updates OpenSSL to version 1.0.2q to address the identified vulnerabilities. Note: The CVSSv2 score used in this advisory reflects CVE-2018-5407, as it is considered the highest risk.

Synopsis

Nessus leverages third-party software to help provide underlying functionality. One third-party component (OpenSSL) was found to contain vulnerabilities, and updated versions have been made available by the providers.

Out of caution and in line with good practice, Tenable opted to upgrade the bundled libraries to address the potential impact of these issues in Nessus. Nessus 8.1.1 updates OpenSSL to version 1.0.2q to address the identified vulnerabilities.

Note: The CVSSv2 score used in this advisory reflects CVE-2018-5407, as it is considered the highest risk.

Solution

Tenable has released Nessus 8.1.1 to address these issues. The installation files can be obtained from the Tenable Downloads Portal (https://www.tenable.com/downloads/nessus)