Local Privilege Escalation Vulnerability in Nessus by Tenable
CVE-2021-20135
6.7MEDIUM
What is CVE-2021-20135?
A local privilege escalation vulnerability exists in Nessus versions 8.15.2 and earlier, which allows an authenticated local administrator to execute specific executables on the Nessus Agent host. This could potentially lead to unauthorized access and manipulation of the system. Tenable has addressed this vulnerability with a fix in Nessus version 10.0.0. Users are advised to upgrade to the latest version from the Tenable Downloads Portal to mitigate associated risks.
Affected Version(s)
Nessus Nessus 8.15.2 and earlier
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved