Vulnerability Details CVE-2018-1154
In SecurityCenter versions prior to 5.7.0, a username enumeration issue could allow an unauthenticated attacker to automate the discovery of username aliases via brute force, ultimately facilitating unauthorized access. Server response output has been unified to correct this issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 60.8%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 3.3
Products affected by CVE-2018-1154
-
cpe:2.3:a:tenable:securitycenter:-
-
cpe:2.3:a:tenable:securitycenter:4.6
-
cpe:2.3:a:tenable:securitycenter:4.7
-
cpe:2.3:a:tenable:securitycenter:5.5.0
-
cpe:2.3:a:tenable:securitycenter:5.5.1
-
cpe:2.3:a:tenable:securitycenter:5.5.2