SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-20077

This could allow a privileged attacker to obtain the token.

MEDIUM 6.7EPSS 0.35%

Does this matter?

Lower severity and a low EPSS score (0.35%). Track it; it rarely justifies an emergency change on its own.

Description

Nessus Agent versions 7.2.0 through 8.2.2 were found to inadvertently capture the IAM role security token on the local host during initial linking of the Nessus Agent when installed on an Amazon EC2 instance. This could allow a privileged attacker to obtain the token.

CVSS 3.1
6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.35% probability · 28th percentile
CISA KEV
Not listed
Affected
tenable/nessus agent
Source
vulnreport@tenable.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.