CVE-2021-20076
HIGHTenable.sc < 5.17.0 - Insecure Deserialization
Title source: ruleDescription
Tenable.sc and Tenable.sc Core versions 5.13.0 through 5.17.0 were found to contain a vulnerability that could allow an authenticated, unprivileged user to perform Remote Code Execution (RCE) on the Tenable.sc server via Hypertext Preprocessor unserialization.
Scores
CVSS v3
8.8
EPSS
0.0338
EPSS Percentile
87.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (1)
tenable/tenable.sc
< 5.17.0
Timeline
Published
Mar 03, 2021
Tracked Since
Feb 18, 2026