CVE-2021-20077

Nessus versions 8.13.2 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to upload a specially crafted file that could lead to gaining administrator privileges on the Nessus host.
References
Link Resource
https://www.tenable.com/security/tns-2021-04-0 Patch Vendor Advisory
https://www.tenable.com/security/tns-2021-07 Not Applicable Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:tenable:nessus_agent:*:*:*:*:*:*:*:*

History

12 Jul 2022, 17:42

Type Values Removed Values Added
CWE CWE-732 NVD-CWE-noinfo

05 Jun 2022, 02:53

Type Values Removed Values Added
References
  • (MISC) https://www.tenable.com/security/tns-2021-04-0 - Patch, Vendor Advisory
References (CONFIRM) https://www.tenable.com/security/tns-2021-07 - (CONFIRM) https://www.tenable.com/security/tns-2021-07 - Patch, Vendor Advisory
CVSS v2 : 2.1
v3 : 4.4
v2 : 7.2
v3 : 6.7

Information

Published : 2021-03-19 19:15

Updated : 2024-02-04 21:23


NVD link : CVE-2021-20077

Mitre link : CVE-2021-20077

CVE.ORG link : CVE-2021-20077


JSON object : View

Products Affected

tenable

  • nessus_agent