First published: Thu Sep 09 2021(Updated: )
Nessus Agent 8.3.0 and earlier was found to contain a local privilege escalation vulnerability which could allow an authenticated, local administrator to run specific executables on the Nessus Agent host. This is different than CVE-2021-20117.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Tenable Nessus Agent | <=8.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20118 is a local privilege escalation vulnerability found in Nessus Agent 8.3.0 and earlier.
CVE-2021-20118 has a severity rating of high (6.7).
Nessus Agent versions 8.3.0 and earlier are affected by CVE-2021-20118.
An authenticated, local administrator could exploit CVE-2021-20118 to run specific executables on the Nessus Agent host.
Yes, it is recommended to upgrade to a version of Nessus Agent that is not vulnerable to CVE-2021-20118.