VulnerabilityModified
CVE-2021-20077
This could allow a privileged attacker to obtain the token.
MEDIUM 6.7EPSS 0.35%
Does this matter?
Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.
Description
Nessus Agent versions 7.2.0 through 8.2.2 were found to inadvertently capture the IAM role security token on the local host during initial linking of the Nessus Agent when installed on an Amazon EC2 instance. This could allow a privileged attacker to obtain the token.
- CVSS 3.1
- 6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.35% probability · 28th percentile
- CISA KEV
- Not listed
- Affected
- tenable/nessus agent
- Source
- vulnreport@tenable.com
References
- https://www.tenable.com/security/tns-2021-04-0Patch, Vendor Advisory
- https://www.tenable.com/security/tns-2021-04-0Patch, Vendor Advisory
- https://www.tenable.com/security/tns-2021-04-0Patch, Vendor Advisory
- https://www.tenable.com/security/tns-2021-04-0Patch, Vendor Advisory
- https://www.tenable.com/security/tns-2021-07Not Applicable, Vendor Advisory
- https://www.tenable.com/security/tns-2021-04-0Patch, Vendor Advisory
- https://www.tenable.com/security/tns-2021-04-0Patch, Vendor Advisory
- https://www.tenable.com/security/tns-2021-04-0Patch, Vendor Advisory
- https://www.tenable.com/security/tns-2021-04-0Patch, Vendor Advisory
- https://www.tenable.com/security/tns-2021-07Not Applicable, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.