PT-2004-3612 · Tenable · Nessus
CVE-2004-2722
·
Publicado
2004-12-31
·
Atualizado
2024-08-08
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nessus version 2.0.10a
Description
The issue concerns the storage of account passwords in plaintext within .nessusrc files. This allows local users to obtain these passwords. It is noted that the vendor has disputed this issue.
Recommendations
For Nessus version 2.0.10a, consider restricting access to .nessusrc files to minimize the risk of password exposure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Nessus