Username Enumeration Vulnerability in Tenable SecurityCenter
CVE-2018-1154
8.8HIGH
What is CVE-2018-1154?
In versions of Tenable SecurityCenter prior to 5.7.0, a vulnerability exists that allows unauthenticated attackers to exploit username enumeration. This flaw enables attackers to systematically discover valid usernames through automated brute force techniques, potentially leading to unauthorized access. To mitigate this risk, server response outputs have been unified, making it more difficult for attackers to ascertain valid usernames.
Affected Version(s)
SecurityCenter All versions prior to 5.7.0
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved