VYPR
Unrated severityNVD Advisory· Published Mar 19, 2021· Updated Aug 3, 2024

CVE-2021-20077

CVE-2021-20077

Description

Nessus Agent versions 7.2.0 through 8.2.2 were found to inadvertently capture the IAM role security token on the local host during initial linking of the Nessus Agent when installed on an Amazon EC2 instance. This could allow a privileged attacker to obtain the token.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Nessus Agent 7.2.0–8.2.2 on EC2 inadvertently captures the IAM role security token during initial linking, allowing a privileged local attacker to obtain it.

Vulnerability

Nessus Agent versions 7.2.0 through 8.2.2, when installed on an Amazon EC2 instance, inadvertently capture the IAM role security token on the local host during the initial linking process. This token is normally used to grant temporary AWS credentials to the instance. The vulnerability exists in the agent's handling of the token during setup.

Exploitation

An attacker with local privileged access (e.g., root or administrator) to the EC2 instance can retrieve the captured IAM role security token from the local filesystem. No network access or user interaction is required beyond having local privileges. The token is captured during the initial linking of the Nessus Agent, so exploitation is possible if the attacker gains access after installation.

Impact

Successful exploitation allows the attacker to obtain the IAM role security token, which can be used to assume the IAM role associated with the EC2 instance. This could lead to unauthorized access to AWS resources and services that the role has permissions for, potentially resulting in data disclosure, modification, or further privilege escalation within the AWS environment.

Mitigation

Tenable released Nessus Agent version 8.2.3 to fix this issue [1]. Users should upgrade to 8.2.3 or later. The fix prevents the inadvertent capture of the IAM token. No workarounds are mentioned in the advisory. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.