HIGH
Code Injection in Rapid7 Nexpose Installer
Published Sep 3, 2020
7.8
HIGHCVSS 3.1
EPSS 0.68%
Description
In Rapid7 Nexpose installer versions prior to 6.6.40, the Nexpose installer calls an executable which can be placed in the appropriate directory by an attacker with access to the local machine. This would prevent the installer from distinguishing between a valid executable called during a Security Console installation and any arbitrary code executable using the same file name.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<6.6.40
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-28508 Advisory
- https://help.rapid7.com/insightvm/en-us/release-notes/index.html?pid=6.6.40 x_refsource_MISCRelease NotesVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-28508 | Advisory | |
| https://help.rapid7.com/insightvm/en-us/release-notes/index.html?pid=6.6.40 | x_refsource_MISCRelease NotesVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner rapid7
Published Sep 3, 2020
Updated Aug 4, 2024
Reserved Jan 21, 2020
Link CVE-2020-7381
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-28508 Assigner rapid7
Published Sep 3, 2020
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2020-28508