7.1
CVSSv3

CVE-2020-5774

Published: 21/08/2020 Updated: 28/08/2020
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Nessus versions 8.11.0 and previous versions were found to maintain sessions longer than the permitted period in certain scenarios. The lack of proper session expiration could allow attackers with local access to login into an existing browser session.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tenable nessus

Vendor Advisories

Nessus versions 8110 and earlier were found to be maintaining sessions longer than the permitted period in certain scenarios The lack of proper session expiration could allow attackers with local access to login into an existing browser session ...

Github Repositories

my public exploit code

exploits and CVE listing my public exploit code CVE-2017-8550 - Microsoft Skype for Business 2016 (aka Lync) wwwexploit-dbcom/exploits/42316 msrcmicrosoftcom/update-guide/en-us/vulnerability/CVE-2017-8550 POC: wwwyoutubecom/watch?v=oGcGVDM7fuk CVE-2018-8474 - Microsoft Lync 2011 for Mac wwwexploit-dbcom/exploits/45936 msrcmicr