> Source: [sk184829](https://support.checkpoint.com/results/sk/sk184829)

# sk184829 - VAPT deep security scan fails when using a non-root scanning user

| Property | Value |
|----------|-------|
| Solution ID | sk184829 |
| Date Created | 2026-04-11 |
| Last Modified | 2026-04-13 |
| Technical Level | Advanced |
| Products | Security Gateway, Security Management Server, Spark Firewall (Locally Managed), Scalable Platforms |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R82.10, R82, R81.20, R82.00.X, R82.10, R82, R81.20, R81.10 (EOS), R81.10 (EOS) |
| OS | Gaia |
| Platform | 9000, 44000, 64000, 1900, 2000, 1600, 1800 |

## Symptoms

- * Vulnerability Assessment and Penetration Testing (VAPT) deep scans fail or return incomplete results when the scanner connects using a user account with a UID other than 0.

* <br />

  The SSH-based scan fails or produces partial output.
* Typical behavior includes permission errors when accessing system resources, for example:

  `
  Scanner logs in as user: nessus_scan`  
  ` ?`  
  ` ??? cat /etc/shadow ? Permission denied`  
  ` ??? rpm -qa ? Partial results`  
  ` ??? cat /proc/1/maps ? Permission denied`  
  ` ??? read /etc/cron.d/ ? Permission denied`  
  ` ??? check SUID binaries ? Incomplete results
  `

## Cause

The scanner used a non-privileged (non-root) user account.

Deep scans require elevated permissions to access critical system files, processes, and configuration data. Without sufficient privileges, the scanner cannot perform all required checks.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
