PT-2021-13776 · Tenable · Nessus Agent

Published

2021-07-21

·

Updated

2022-07-12

·

CVE-2021-20106

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Nessus Agent versions 8.2.5 and earlier
Description: A privilege escalation issue was discovered, allowing a Nessus administrator user to upload a specially crafted file, potentially gaining administrator privileges on the Nessus host.
Recommendations: For Nessus Agent versions 8.2.5 and earlier, update to a version later than 8.2.5 to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-20106

Affected Products

Nessus Agent