CVE-2021-20076: High severity tenable.sc vulnerability
Published Mar 3, 2021
·Updated
Tenable.sc and Tenable.sc Core versions 5.13.0 through 5.17.0 were found to contain a vulnerability that could allow an authenticated, unprivileged user to perform Remote Code Execution (RCE) on the Tenable.sc server via Hypertext Preprocessor unserialization.
Affected Software
1 affected component
Tenable Tenable.Sc>=5.13.0<=5.17.0
Event History
Mar 3, 2021
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Tenable.sc vulnerability?
The vulnerability ID is CVE-2021-20076.
2
What is the severity rating of CVE-2021-20076?
CVE-2021-20076 has a severity rating of 8.8 (high).
3
Which versions of Tenable.sc are affected by CVE-2021-20076?
Tenable.sc versions 5.13.0 through 5.17.0 are affected by CVE-2021-20076.
4
How can an attacker exploit the vulnerability in CVE-2021-20076?
An authenticated, unprivileged user can perform Remote Code Execution (RCE) on the Tenable.sc server via Hypertext Preprocessor unserialization.
5
Is there a fix available for CVE-2021-20076?
Yes, Tenable.sc and Tenable.sc Core versions 5.18.0 and later include a fix for CVE-2021-20076. It is recommended to upgrade to the latest version.