PT-2004-3612 · Tenable · Nessus
Published
2004-12-31
·
Updated
2024-08-08
·
CVE-2004-2722
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nessus version 2.0.10a
Description
The issue concerns the storage of account passwords in plaintext within .nessusrc files. This allows local users to obtain these passwords. It is noted that the vendor has disputed this issue.
Recommendations
For Nessus version 2.0.10a, consider restricting access to .nessusrc files to minimize the risk of password exposure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nessus