Vulnerability Description
In SecurityCenter versions prior to 5.7.0, a username enumeration issue could allow an unauthenticated attacker to automate the discovery of username aliases via brute force, ultimately facilitating unauthorized access. Server response output has been unified to correct this issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tenable | Securitycenter | < 5.7.0 |
References
- http://www.securitytracker.com/id/1041431Third Party AdvisoryVDB Entry
- https://www.tenable.com/security/tns-2018-11PatchVendor Advisory
- http://www.securitytracker.com/id/1041431Third Party AdvisoryVDB Entry
- https://www.tenable.com/security/tns-2018-11PatchVendor Advisory
FAQ
What is CVE-2018-1154?
CVE-2018-1154 is a vulnerability with a CVSS score of 8.8 (HIGH). In SecurityCenter versions prior to 5.7.0, a username enumeration issue could allow an unauthenticated attacker to automate the discovery of username aliases via brute force, ultimately facilitating u...
How severe is CVE-2018-1154?
CVE-2018-1154 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1154?
Check the references section above for vendor advisories and patch information. Affected products include: Tenable Securitycenter.