VYPR

Nessus Agent Tray App

by Tenable

CVEs (9)

  • CVE-2025-36640HigJan 13, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability has been identified in the installation/uninstallation of the Nessus Agent Tray App on Windows Hosts which could lead to escalation of privileges.

  • CVE-2020-5793HigNov 5, 2020
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in Nessus versions 8.9.0 through 8.12.0 for Windows & Nessus Agent 8.0.0 and 8.1.0 for Windows could allow an authenticated local attacker to copy user-supplied files to a specially constructed path in a specifically named user directory. An attacker could…

  • CVE-2021-20135MedNov 3, 2021
    risk 0.44cvss 6.7epss 0.00

    Nessus versions 8.15.2 and earlier were found to contain a local privilege escalation vulnerability which could allow an authenticated, local administrator to run specific executables on the Nessus Agent host. Tenable has included a fix for this issue in Nessus 10.0.0. The…

  • CVE-2021-20118MedSep 9, 2021
    risk 0.44cvss 6.7epss 0.00

    Nessus Agent 8.3.0 and earlier was found to contain a local privilege escalation vulnerability which could allow an authenticated, local administrator to run specific executables on the Nessus Agent host. This is different than CVE-2021-20117.

  • CVE-2021-20117MedSep 9, 2021
    risk 0.44cvss 6.7epss 0.00

    Nessus Agent 8.3.0 and earlier was found to contain a local privilege escalation vulnerability which could allow an authenticated, local administrator to run specific executables on the Nessus Agent host. This is different than CVE-2021-20118.

  • CVE-2021-20100MedJun 28, 2021
    risk 0.44cvss 6.7epss 0.00

    Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Nessus host. This is different than CVE-2021-20099.

  • CVE-2021-20099MedJun 28, 2021
    risk 0.44cvss 6.7epss 0.00

    Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Nessus host. This is different than CVE-2021-20100.

  • CVE-2021-20077MedMar 19, 2021
    risk 0.44cvss 6.7epss 0.00

    Nessus Agent versions 7.2.0 through 8.2.2 were found to inadvertently capture the IAM role security token on the local host during initial linking of the Nessus Agent when installed on an Amazon EC2 instance. This could allow a privileged attacker to obtain the token.

  • CVE-2021-20106MedJul 21, 2021
    risk 0.42cvss 6.5epss 0.01

    Nessus Agent versions 8.2.5 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to upload a specially crafted file that could lead to gaining administrator privileges on the Nessus host.