7.2
CVSSv2

CVE-2021-20077

Published: 19/03/2021 Updated: 28/10/2022
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.7 | Impact Score: 5.9 | Exploitability Score: 0.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Nessus Agent versions 7.2.0 up to and including 8.2.2 were found to inadvertently capture the IAM role security token on the local host during initial linking of the Nessus Agent when installed on an Amazon EC2 instance. This could allow a privileged malicious user to obtain the token.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tenable nessus agent

Vendor Advisories

Nessus versions 8132 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to upload a specially crafted file that could lead to gaining administrator privileges on the Nessus host ...
Nessus Agent versions 720 through 822 were found to inadvertently capture the IAM role security token on the local host during initial linking of the Nessus Agent when installed on an Amazon EC2 instance This could allow a privileged attacker to obtain the token Additionally, one third-party component (OpenSSL) was found to contain vulnerabi ...