Credential Exposure Through Environment Variables

high Nessus Plugin ID 345665

Synopsis

Discovers environment variables that may expose secrets to attackers

Description

This plugin identifies credentials or secrets that are potentially exposed to malicious actors by environment variables on the target host.

Attackers who establish a foothold on a target can escalate or move laterally using passwords, access tokens or API keys stored in local environment variables. Even identities such as user names or service accounts can become valuable clues to aid exploitation.

This plugin identifies potential exposure of this sensitive data based on the names of environment variables that appear in product documentation or examples which are often used to ease access to cloud services, enterprise APIs or remote hosts.

Solution

Verify the finding, this finding is based primarily on environment variable names which could produce false positives. Modify access procedures to use a credential manager or to manually provision credentials from a secure location.

Plugin Details

Severity: High

ID: 345665

File Name: environment_credential_exposure.nasl

Version: 1.1

Type: Local

Agent: windows, macosx, unix

Family: General

Published: 9/14/2026

Updated: 9/14/2026

Supported Sensors: Nessus Agent, Nessus

Risk Information

CVSS Score Rationale: Tenable score based on exploit profile.

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Vector: CVSS2#AV:L/AC:L/Au:M/C:C/I:C/A:C

CVSS Score Source: manual

CVSS v3

Risk Factor: High

Base Score: 8.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CVSS Score Source: manual

Vulnerability Information

Required KB Items: Host/env_vars/enumerated