CVE-2025-0760 Details
Description
A Credential Disclosure vulnerability exists where an administrator could extract the stored SMTP account credentials due to lack of encryption.
A credential disclosure vulnerability exists in Tenable Identity Exposure versions through 3.77.8, allowing administrators to extract stored SMTP account credentials due to a lack of encryption. This vulnerability could be exploited by accessing the application with administrative privileges and retrieving the unencrypted credentials.
Tenable has released version 3.77.9, which addresses this vulnerability. The update can be downloaded from the Tenable Downloads Portal.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 26, 2025CISA-ADP
Assessed Feb 26, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tenable.com/security/tns-2025-01 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Tenable Identity Exposure | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 26, 2025 | New CVE Received | [email protected] |
Volerion