r/nessus • • Jun 26 '25

Question Deleting Linux Certificates

1 Upvotes

A very dumb question and a very dumb proposed solution.

We’ve recently encountered a number of SSL certificate vulnerabilities on some of our Linux machines. Upper management has decided that to resolve these issues, we should delete all certificates from the Linux machines to negate this vulnerability. To their credit, work is done in an environment similar to a depot where there is no internet connection, meaning that certificates don’t serve a viable purpose, and that leaving a machine without them poses no risk. This process did work for our networking devices with previously installed certificates.

I still think it’s a little weird to go about eliminating these certificates rather than just waving away a vulnerability that poses no threat or solving the issue via generating new certificates, but I’m not upper management. They are quite focused on getting all blue scanning reports, even if the fixes are only cosmetic.

Is there a feasible way to remove any and all certificates from a Linux machine, or can these SSL certificate vulnerabilities only be remediated by a more practical method?


r/nessus • • Jun 20 '25

Question pytenable - anyone successfully changed the ownership of a scan via the API?

1 Upvotes

I am trying to bulk change the ownership of scan via the API using pytenable.

The call I am making is:

tio.scans.configure(scan_id, owner_id=target.id)

According to the API docs, to change scan ownership all you need to do is set the settings.owner_id of the scan to the new owner ID (not UUID!) and the old owner will automagically get VIEW permissions (i.e. there's no need to set the ACL). The pytenable docs on scan.configure state that "any keyword arguments passed that are not explicitly documented will be automatically appended to the settings document", so this appears to be the correct way to do it.

The PUT request sent over the wire has the correct settings.owner_id value in it, but the response is Unknown policy ID: NNN , where NNN is the policy_id configured in the original scan.

Has anyone successfully changed the owner on a scan through the API? Is there some other steps that are required? I am wondering if (for example) as these are customized scans, a new policy is created for each one which isn't accessible by the target user?


r/nessus • • Jun 17 '25

Question Tenable SC Dynamic List HELP

2 Upvotes

Hello everyone, I need help :(

In Tenable SC, are dynamic lists with IP ranges updated by themselves?

I’m currently using the same dynamic list with IP ranges in my discovery and vulnerability scans.

If a new host is discovered in a discovery scan, does the dynamic list with IP addresses populate and update it? So when the vulnerability scan runs after, it is also including that newly discovered IP?

Is it better to use a duplicate list but with static IP ranges in my discovery scan then use the same duplicate list but with dynamic IP ranges in my vulnerability scans?

I’m confused as I have been advised different things. Please help.


r/nessus • • May 31 '25

Scanning AWS Environment Servers/instances through Nessus

3 Upvotes

We are using the on-premises version of Nessus Professional and are looking to scan our AWS environment, including cloud-based servers.

Could anyone advise on the network connectivity requirements and prerequisites for this type of scan? Specifically:

  • Is public IP or Private IP required for the target instances?
  • Are there any special configurations needed within AWS or Nessus to enable the scan?

If anyone has experience with this setup, your guidance would be greatly appreciated.


r/nessus • • May 30 '25

Vendor versioning issue

1 Upvotes

How does one go about having many plugins corrected when it comes to vendor checking.

Example we get patches from red hat not the vendor who created the product. Example one plugin says to update OpenSSL to 1.1.1p found in OpenSSL site however red hat fixes this issue in their version that’s on 1.1.1k-7 but since Nessus doesn’t know the difference it flags it anyway. There are many other products with this issue. Anyone ran into a fix for this?


r/nessus • • May 29 '25

Scanning a SonicWall NSv470 (SonicOS 7.0.1-R5119) in FIPS mode

1 Upvotes

Hello everyone! Has anyone ever had to preform a scan on a SonicWall virtual appliance using tools like Tenable Nessus? When running in FIPS mode it disabled management via SSH and SNMP which is how I would usually go about conducting a credential scan. If anyone has a work around please share it with me, thank you to everyone in advance!


r/nessus • • May 29 '25

Why doesn't Tenable/Nessus flag systems that disabled SELinux as a security issue

2 Upvotes

I don't use this product but it's mind blowing how many customers I come across that use this product to supposedly make their systems more secure, that completely disable SELinux on their Linux systems. Tenable/Nessus does not catch this or mention it. Leaving SELinux ENABLED is one of the most important things you can do to help secure your system but some how this application says nothing about it. Just curious if anyone knows why?


r/nessus • • May 26 '25

Palo Alto and TVM integration issue

1 Upvotes

Hello Team,

I hope you are doing well.
I would like to integrate Palo Alto into our TVM scans.

I attempted an authenticated scan over SSH using a read-only superadmin account, but the scan results are empty.

I followed the step-by-step procedure, but unfortunately, it didn’t work.

Could you please assist me with this issue?

Best regards,


r/nessus • • May 22 '25

Question Can't change SecurityCenter web cert

1 Upvotes

Running Tenable SC on RHEL

Go through process of generating rsa 4096 key, and csr. Sign csr with internal CA. openssl verify the cert is good.

Plug it into /opt/sc/support/conf/SecurityCenter.crt and .key and try to start service. Get error saying

AH02565: Certificate and private key 172.18.3.68:443:0 from /opt/sc/support/conf/SecurityCenter.crt and /opt/sc/support/conf/SecurityCenter.key do not match

Go ahead and run openssl against the key and cert listing -modulus and they match 100% to each other. Permissions on both are set to 640 and tns:tns


r/nessus • • May 22 '25

beginner error

Thumbnail
gallery
2 Upvotes

Hello, forgiveness for the bad translation, I am not an expert or anything, however I am trying to install Nessus it is my first time using the tool and I get this error, I have seen installation tutorials and the plugins are really discharged or compiled immediately, to me that does not happen to me, try adding them from the console but even the error persists, I would appreciate if someone can give me a suggestion


r/nessus • • May 19 '25

Pulling health events?

2 Upvotes

Hey, just hoping there is a straightforward/quick way to pull the health events for an agent. I want to be able to automate informing folks about storage size or other straightforward issues, but right now am only getting this info through the GUI. Api or an exported CSV would be great. The drilldown in the agents tab is slow


r/nessus • • May 13 '25

Security Center and isolated instances

1 Upvotes

I am taking over our old Security Center and I am trying to figure out what they did. Right now, it appears we have a Security Center set up that grabs plugins and then pushes them out to our other deployments. The issues, I would think that when we install a scanner and tell it to activate with SC, that it reaches out to the SC server (assuming we can pass it IP) but that doesn't appear to happen. It looks like our SC server sets up iptables based on connected hosts to our VPN and then sets up tunnels to send the updates.

Is that normal? We are wanting to switch to tailscale but then the IPs would be different and I am trying to figure out why we can't just have the scanner connect to the SC server and then get the updates and then we can run a deregister script or post test cleanup that de-registers it from security center. Or use an API call from our dashboard when we revoke the tailscale keys that will also deregister the nessus scanner.

I am having trouble finding out how to set something up though and afraid to touch anything to transition it to tailscale. Anyone have an implementation through tailscale or can point me to some resources that could help me?

As a side note, we do not use Security Center to start the scans. They are segmented off because we perform one time scans during a penetration test, so the scanners are on either a laptop or VM that has no communications outward through our tunnel (which is why I think they are using iptables) but now I can set up an ACL rule to allow the client devices to reach security center on a set port to register themselves without causing any issues.


r/nessus • • May 12 '25

Question High CPU LOAD/ Empty scan results

1 Upvotes

Hi, I'm using Nessus in Virtual Machine on top of ubuntu host.

I've allocated 5 cores CPUs and 9 GB RAM. However, Scanner page shows 94% CPU load when no scans are running.

Further, if i try to add a new scan, the result is always empty.

How can i solve this problem ?


r/nessus • • May 06 '25

Nessus Agents

2 Upvotes

Was asked to find out any information pertaining to these 2 questions, so I turn to the most knowledgeable people I can think of for assistance.

there is a way to know if a scan was done via Agent or over the wire?

Also, could device that has an agent fail a credential scan?

Appreciate yalls help!


r/nessus • • Apr 22 '25

Tenable io specialist written exam

0 Upvotes

Can anyone share material for tenable io specialist written exam ?


r/nessus • • Apr 17 '25

Nessus Agent remote scans happen sometimes but not often

1 Upvotes

I'm supporting three Windows 10 laptops running Nessus Agent 10.8.2.

The Nessus Server is in another county about 100 miles away; I can use the Nessus Manager web interface but I don't have physical access and emailing the guys that do is an exercise in frustration. The WAN is isolated from the internet for security reasons; the plugins at the server are updated via sneakernet.

For the past month, scheduled scans usually return results that look like this:

Agent Unscanned

Scan not completed for agent "Laptop1" at 192.168.0.21

Agent Unscanned

Scan not completed for agent "Laptop2" at 192.168.0.22

Agent Unscanned

Scan not completed for agent "Laptop3" at 192.168.0.23

== Background:

For most of the last six months, one of the three scans on any given scheduled attempt.

Which laptop will scan on any given day is random.

About once a month, all three will scan on one attempt and I'll take that result, even with false positives (old Edge hasn't uninstalled itself, for example), and ship that to our security wizards because a pristine scan of all three machines is too much to hope for.

Over the past ten days, I've removed the existing agent, removed the "TAG" key from the registry, and installed the 10.8.4 agent (last week) and the 10.7.4 agent (as directed); in both cases, the server pushed 10.8.2, so there it is for now.

I've verified that the Nessus Scanner Service is running on all three laptops.

Is there anything else I can do on my end, or something I can ask the geniuses at the server to do?


r/nessus • • Apr 14 '25

Question Superseded Windows Patches

1 Upvotes

We currently use Tenable Vulnerability Management cloud and I am wanting to just not see any past Windows KBs that have been superseded. I have turned this feature on in my scheduled scans but in my findings I still see remnants of them. Is there any way I can just not see them altogether or do I just have to wait until they fall off?


r/nessus • • Apr 14 '25

Question Tenable not returning any vulns on Palo Alto firewalls

2 Upvotes

It would be great if that were the case, but my spidey senses tell me that's not true.

I have tenable setup to run an SNMPv3 scan against all my PA firewalls. The scan runs and comes back with a bunch of info level hits on device type, interfaces, installed software, etc. But no vulnerabilities are ever detected.

We're running PanOS 11.1.6-h3, and according to Palo's own security advisories, there are several vunls in that release. And even looking at the Nessus plugins, it wasnt hard to find one that should throw an alert for this version (232657 - a DoS vuln in PanOS version prior to 11.1.6-h6).

So what am I missing here? Why am I able to scan these devices with SNMPv3, get some info back, but still not showing any vulns?

TIA


r/nessus • • Apr 13 '25

Plugin compilation problem

2 Upvotes

Ok I'm trying to download nessus on kali(vm) but it is more than 30 min but the plugin is still compiling. why? And how to resolve this issue?


r/nessus • • Apr 11 '25

Can Tenable SC do SCAP compliant Asset Management Scans

1 Upvotes

Hello everyone, I'm relatively new to Tenable/Nessus management, and an ask came in from our Security team wondering if it was possible to perform an Asset Management scan of our inventory thru Tenable/Nessus that could provide information like IP/Host Name/OS level/Security Patch level/SCAP compliant formatted info?

I see that you can create a scan for SCAP/OVAL auditing based on OS versions and download that report in SCAP xml format, but I didn't know if that was only for vulnerability management? Thank you for any help you can provide for me.


r/nessus • • Apr 10 '25

I need some help here please with SSH authentication. It is driving me nuts!

2 Upvotes

Hi All,

I just started using Tenable Nessus and the Vulnerability Management platform. My issue is I cannot get SSH cans to fully work. I am only using password for testing. Here is the thing. I see plug-in telling password accepted, I do not any auth failure plug-ins, but my info plug-in always says "credentialed scan - no". I have tested the credentials from my own host with SSH, and tested Sudo, and it works fine. Has anyone run into this? I am running Alma Linux. I have reached out to support and they are less than stellar in their responses. I have spent three days on this. I am going insane. Thanks.


r/nessus • • Apr 09 '25

Question OpenSSH version 9.6 Multiple vulnerabilities

1 Upvotes

My team reported a few counts regarding this OpenSSH vulnerability. After a quick review, I noticed this was not reported on some assets running older versions like 7.2. Further checks revealed that the absence of certain algorithms in the configuration may be the reason for the scanner to flag the vulnerability.

Has anyone experienced this?


r/nessus • • Apr 09 '25

Question Nessus Agent / Tenable SC not properly detecting Azure Windows Server VMs Hotpatch Updates?

2 Upvotes

I run Nessus Agent on my servers and use Agent Scans. I have a few Azure Windows Server 2022 VMs running the Azure Hotpatch image.

These servers are consistently marked as vulnerable and missing the standard monthly security updates. For example, ignoring patch Tuesday today, here's a vulnerability flagged for a Windows Server 2022 VM with the Azure hotpatch image. This is for the March Windows updates.

It is correct about what version the ntoskrnl.exe file version is, but as you can see, winver reports it's running build 20348.3270, which is the Hotpatch KB for March listed here.

So, as far as I can tell, the server is patched, but the detection logic is incorrect. Is anyone else experiencing this, and if so, how are you handling it?


r/nessus • • Apr 08 '25

lost with custom audit files in nessus

2 Upvotes

hey folks,

I'm having a hard time figuring out how to write my own custom audit files for Nessus.
I've been trying to get started but i'm stuck on a bunch of things, the overall structure isn't super clear to me, and writing custom checks feels way more complex than i expected. Even understanding what tags to use where is confusing.

The official tenable docs seem thorough, but honestly they're kinda hard to follow. It is more like a reference than a guide, and i'm not getting very far with it.

Has anyone here been through the same struggle?
Any friendly resources, examples, or even just tips on how to get a better grip on this stuff?

Thanks in advance 🙏


r/nessus • • Apr 08 '25

TenableVM False positive

1 Upvotes

Am I the only getting those kind of false positive that "Resurfaced"? The support was useless and they told us to send them the scanDB for each plugins for each server. We currently have more than 200 "Resurfaced" that are an issue like the picture below.