[R1] Nessus Network Monitor 5.11.0 Fixes Multiple Third-party Vulnerabilities

Related Vulnerabilities: CVE-2015-9251   CVE-2016-2542   CVE-2019-11358   CVE-2019-1547   CVE-2019-1552  

Nessus Network Monitor leverages third-party software to help provide underlying functionality. Several third-party components (OpenSSL, jQuery and moment.js) were found to contain vulnerabilities, and updated versions have been made available by the providers. Out of caution and in line with good practice, Tenable opted to upgrade the bundled OpenSSL, jQuery and moment.js components to address the potential impact of these issues. Nessus Network Monitor 5.11.0 updates OpenSSL to version 1.1.1d, jQuery to 3.4.1 and moment.js to 2.24.0 to address the identified vulnerabilities. Note: The CVSSv2 score used in this advisory reflects CVE-2016-2542, as it is considered the highest risk.

Synopsis

Nessus Network Monitor leverages third-party software to help provide underlying functionality. Several third-party components (OpenSSL, jQuery and moment.js) were found to contain vulnerabilities, and updated versions have been made available by the providers.

Out of caution and in line with good practice, Tenable opted to upgrade the bundled OpenSSL, jQuery and moment.js components to address the potential impact of these issues. Nessus Network Monitor 5.11.0 updates OpenSSL to version 1.1.1d, jQuery to 3.4.1 and moment.js to 2.24.0 to address the identified vulnerabilities.

Note: The CVSSv2 score used in this advisory reflects CVE-2016-2542, as it is considered the highest risk.

Solution

Tenable has released Nessus Network Monitor 5.11.0 to address these issues. The patch can be obtained from the Tenable Downloads Portal (https://www.tenable.com/downloads/nessus-network-monitor).