CVE-2020-5774 Vulnerability Details

  /     /     /  

CVE-2020-5774 Metadata Quick Info

CVE Published: 21/08/2020 | CVE Updated: 04/08/2024 | CVE Year: 2020
Source: tenable | Vendor: n/a | Product: Tenable Nessus
Status : PUBLISHED

CVE-2020-5774 Description

Nessus versions 8.11.0 and earlier were found to maintain sessions longer than the permitted period in certain scenarios. The lack of proper session expiration could allow attackers with local access to login into an existing browser session.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Insufficient Session Expiration
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).