Credential Disclosure Vulnerability in SMTP Account Management by Tenable
CVE-2025-0760

2.7LOW

Key Information:

Vendor

Tenable

Vendor
CVE Published:
26 February 2025

What is CVE-2025-0760?

A credential disclosure issue has been identified in Tenable's products involving SMTP account management. Due to inadequate encryption mechanisms, an attacker with administrative access could extract stored SMTP account credentials, potentially compromising sensitive email communications and system integrity. Organizations using affected Tenable products should immediately assess their configurations and consider implementing additional safeguards to protect stored credentials.

Affected Version(s)

Tenable Identity Exposure Windows 0

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.