← Vulnerability feed

Vulnerability record · CVE-2018-1154 · published 2 August 2018

CVE-2018-1154: Tenable security center vulnerability

Tenable · Security Center

In SecurityCenter versions prior to 5.7.0, a username enumeration issue could allow an unauthenticated attacker to automate the discovery of username aliases via brute force, ultimately facilitating unauthorized access. Server response output has been unified to correct this issue.

8.8 CVSS 3.0 High EPSS 0.67% · top 49.9%
8.8CVSS 3.0 base score, v2 3.3
0.67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Aug 2026Last modified by NVD

Description

In SecurityCenter versions prior to 5.7.0, a username enumeration issue could allow an unauthenticated attacker to automate the discovery of username aliases via brute force, ultimately facilitating unauthorized access. Server response output has been unified to correct this issue.

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securitytracker.com/id/1041431 Third Party AdvisoryVDB Entry
https://www.tenable.com/security/tns-2018-11 PatchVendor Advisory
http://www.securitytracker.com/id/1041431 Third Party AdvisoryVDB Entry
https://www.tenable.com/security/tns-2018-11 PatchVendor Advisory

Track CVE-2018-1154 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-11049Php double free vulnerabilityIn PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4…EPSS 4.2%9.4CVE-2026-19681Tenable security center os command injection vulnerabilityAn authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by…EPSS 9.9%9.4CVE-2026-19682Tenable security center os command injection vulnerabilityA command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary co…EPSS 2.8%9.4CVE-2026-19626Tenable security center vulnerabilityA remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user …EPSS 1.9%9.4CVE-2026-64878Tenable security center os command injection vulnerabilityUnvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a…EPSS 0.80%9.4CVE-2026-64879Tenable security center os command injection vulnerabilityA filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell …EPSS 2.3%9.4CVE-2026-64877Tenable security center improper input validation vulnerabilityAn authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.EPSS 0.32%8.8CVE-2023-2005Tenable nessus uncontrolled search path element vulnerabilityVulnerability in Tenable Tenable.Io, Tenable Nessus, Tenable Security Center.This issue affects Tenable.Io: before Plugin Feed ID #202306261202 ; Nes…EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2018-1154), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.