---
id: CVE-2018-1154
title: >-
  In SecurityCenter versions prior to 5.7.0, a username enumeration issue could
  allow an unauthenticated attacker to automate the discovery of username
  aliases via brute force, ultimately facilitating unauthorized access
summary: >-
  In SecurityCenter versions prior to 5.7.0, a username enumeration issue could
  allow an unauthenticated attacker to automate the discovery of username
  aliases via brute force, ultimately facilitating unauthorized access. Server
  response o…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: tenable
product: security_center
affected:
  - security_center < 5.7.0
patched:
  - security_center 5.7.0
published: '2018-08-02'
updated: '2026-08-17'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-1154'
references:
  - url: 'http://www.securitytracker.com/id/1041431'
    label: vulnreport@tenable.com
  - url: 'https://www.tenable.com/security/tns-2018-11'
    label: vulnreport@tenable.com
  - url: 'http://www.securitytracker.com/id/1041431'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.tenable.com/security/tns-2018-11'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00673
epssPercentile: 0.50694
ingestedAt: '2026-08-17T14:55:58.704Z'
---

## Overview

In SecurityCenter versions prior to 5.7.0, a username enumeration issue could allow an unauthenticated attacker to automate the discovery of username aliases via brute force, ultimately facilitating unauthorized access. Server response output has been unified to correct this issue.

## Affected

- `security_center < 5.7.0`

## Remediation

Upgrade past the affected range:

- `security_center 5.7.0`
