VDB

CVE-2021-20077

CVE-2021-20077 PUBLISHED CVSS 7.199999809265137 HIGH

Nessus Agent versions 7.2.0 through 8.2.2 were found to inadvertently capture the IAM role security token on the local host during initial linking of the Nessus Agent when installed on an Amazon EC2 instance. This could allow a privileged attacker to obtain the token.

EPSS 0.04% · 13.3th percentile

Risk Scores

CVSS 2.0
7.199999809265137
EPSS Score
0.04%
13.3th percentile

Affected Products

VendorProductVersions
n/aTenable Nessus Agent*
TenableNessus
tenablenessus_agent7.2.0

Timeline

  • Mar 19, 2021 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›