Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p52h-rp33-x9gq

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.5

Описание

The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key exchange and other important functions. As a result, it falls back to allowing ALL algorithms supported by the relevant version of OpenSSH and makes the installations vulnerable to a range of MITM, downgrade, and decryption attacks.

The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key exchange and other important functions. As a result, it falls back to allowing ALL algorithms supported by the relevant version of OpenSSH and makes the installations vulnerable to a range of MITM, downgrade, and decryption attacks.

EPSS

Процентиль: 40%
0.0018
Низкий

8.5 High

CVSS3

Дефекты

CWE-327

Связанные уязвимости

CVSS3: 8.5
nvd
больше 8 лет назад

The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key exchange and other important functions. As a result, it falls back to allowing ALL algorithms supported by the relevant version of OpenSSH and makes the installations vulnerable to a range of MITM, downgrade, and decryption attacks.

EPSS

Процентиль: 40%
0.0018
Низкий

8.5 High

CVSS3

Дефекты

CWE-327