Certificate Validation Flaw in Tenable.sc Client Configuration

Certificate Validation Flaw in Tenable.sc Client Configuration

CVE-2021-27018 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed by an internal certificate authority to not be properly validated. This issue only affects clients that are configured to utilize Tenable.sc as the vulnerability data source.

Learn more about our Internal Network Penetration Testing.