Back

MEDIUM

Unquoted Path in Rapid7 Nexpose Installer

Published Sep 3, 2020

Description

Rapid7 Nexpose installer version prior to 6.6.40 contains an Unquoted Search Path which may allow an attacker on the local machine to insert an arbitrary file into the executable path. This issue affects: Rapid7 Nexpose versions prior to 6.6.40.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner rapid7
Published Sep 3, 2020
Updated Aug 4, 2024
Reserved Jan 21, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner rapid7
Published Sep 3, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-28509