Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pcgq-484v-rqvh

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In Rapid7 Nexpose installer versions prior to 6.6.40, the Nexpose installer calls an executable which can be placed in the appropriate directory by an attacker with access to the local machine. This would prevent the installer from distinguishing between a valid executable called during a Security Console installation and any arbitrary code executable using the same file name.

In Rapid7 Nexpose installer versions prior to 6.6.40, the Nexpose installer calls an executable which can be placed in the appropriate directory by an attacker with access to the local machine. This would prevent the installer from distinguishing between a valid executable called during a Security Console installation and any arbitrary code executable using the same file name.

EPSS

Процентиль: 58%
0.00371
Низкий

Связанные уязвимости

CVSS3: 5.8
nvd
больше 5 лет назад

In Rapid7 Nexpose installer versions prior to 6.6.40, the Nexpose installer calls an executable which can be placed in the appropriate directory by an attacker with access to the local machine. This would prevent the installer from distinguishing between a valid executable called during a Security Console installation and any arbitrary code executable using the same file name.

EPSS

Процентиль: 58%
0.00371
Низкий