Local Privilege Escalation in Nessus Agent by Tenable
CVE-2021-20117

6.7MEDIUM

Key Information:

Vendor

Tenable

Vendor
CVE Published:
9 September 2021

What is CVE-2021-20117?

The Nessus Agent, prior to version 8.3.0, contains a vulnerability that allows an authenticated local administrator to execute specific programs on the host system. This flaw poses a risk of unauthorized privilege escalation, potentially allowing malicious users with local access to exploit these capabilities and execute unwarranted actions. It is important for users of Nessus Agent to apply necessary patches and updates to safeguard their systems.

Affected Version(s)

Nessus Agent Nessus Agent 8.3.0 and earlier

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.