CVE-2021-20076

HIGH

Tenable.sc < 5.17.0 - Insecure Deserialization

Title source: rule

Description

Tenable.sc and Tenable.sc Core versions 5.13.0 through 5.17.0 were found to contain a vulnerability that could allow an authenticated, unprivileged user to perform Remote Code Execution (RCE) on the Tenable.sc server via Hypertext Preprocessor unserialization.

Scores

CVSS v3 8.8
EPSS 0.0338
EPSS Percentile 87.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (1)

tenable/tenable.sc < 5.17.0

Timeline

Published Mar 03, 2021
Tracked Since Feb 18, 2026