Tenable SecurityCenter 5.4.x <= 5.4.3 PHP Object Deserialization Remote File Deletion (TNS-2017-05)

Medium Nessus Plugin ID 97575


An application installed on the remote host is affected by a PHP object deserialization vulnerability.


According to its version, the installation of Tenable SecurityCenter on the remote host is affected by a PHP object deserialization vulnerability in the PluginParser.php script. An authenticated, remote attacker can exploit this, by uploading a specially crafted PHP object, to delete arbitrary files on the remote host.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.


Apply the appropriate patch referenced in the vendor advisory.

See Also


Plugin Details

Severity: Medium

ID: 97575

File Name: securitycenter_5_4_3_tns_2017_05.nasl

Version: 1.4

Type: local

Family: Misc.

Published: 2017/03/07

Modified: 2017/08/28

Dependencies: 71158

Risk Information

Risk Factor: Medium


Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:N


Base Score: 4.3

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Vulnerability Information

CPE: cpe:/a:tenable:securitycenter

Required KB Items: Host/SecurityCenter/Version

Patch Publication Date: 2017/02/17

Vulnerability Publication Date: 2017/02/17

Reference Information

OSVDB: 152286