Username Enumeration Vulnerability in Tenable SecurityCenter
CVE-2018-1154

8.8HIGH

Key Information:

Vendor

Tenable

Vendor
CVE Published:
2 August 2018

What is CVE-2018-1154?

In versions of Tenable SecurityCenter prior to 5.7.0, a vulnerability exists that allows unauthenticated attackers to exploit username enumeration. This flaw enables attackers to systematically discover valid usernames through automated brute force techniques, potentially leading to unauthorized access. To mitigate this risk, server response outputs have been unified, making it more difficult for attackers to ascertain valid usernames.

Affected Version(s)

SecurityCenter All versions prior to 5.7.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.