Back to Database
Status published
Low
CVE-2004-2722
Nessus 2.0.10a stores account passwords in plaintext in .nessusrc files,...
Vulnerability Description
Nessus 2.0.10a stores account passwords in plaintext in .nessusrc files, which allows local users to obtain passwords. NOTE: the original researcher reports that the vendor has disputed this issue
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-2722
Credits & Attribution
No credits recorded in the NVD database.
References
More from nessus
View All →CVE-2010-2989
nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus...
Medium
5
CVE-2010-2914
Cross-site scripting (XSS) vulnerability in nessusd_www_server.nbin in the Nessus Web...
Medium
4.3
CVE-2007-4062
The SCANCTRL.ScanCtrlCtrl.1 ActiveX control in scan.dll in Nessus Vulnerability Scanner...
High
7.8
CVE-2007-4061
Directory traversal vulnerability in a certain ActiveX control in Nessus...
Critical
9.3
CVE-2007-4031
Directory traversal vulnerability in a certain ActiveX control in Nessus...
High
7.8
Affected Vendor
nessus
View all reports →Affected Software
nessus
Vulnerable Versions:
2.0.10a
Timeline
Official Publish:
October 6th, 2007
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.