Количество 2
Количество 2
CVE-2026-1814
A security vulnerability has been identified in Rapid7 Nexpose. Remediation is in progress.
GHSA-jgf7-8v7j-fwwh
Rapid7 Nexpose versions 6.4.50 and later are vulnerable to an insufficient entropy issue in the CredentialsKeyStorePassword.generateRandomPassword() method. When updating legacy keystore passwords, the application generates a new password with insufficient length (7-12 characters) and a static prefix 'p', resulting in a weak keyspace. An attacker with access to the nsc.ks file can brute-force this password using consumer-grade hardware to decrypt stored credentials.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-1814 A security vulnerability has been identified in Rapid7 Nexpose. Remediation is in progress. | 0% Низкий | 6 дней назад | ||
GHSA-jgf7-8v7j-fwwh Rapid7 Nexpose versions 6.4.50 and later are vulnerable to an insufficient entropy issue in the CredentialsKeyStorePassword.generateRandomPassword() method. When updating legacy keystore passwords, the application generates a new password with insufficient length (7-12 characters) and a static prefix 'p', resulting in a weak keyspace. An attacker with access to the nsc.ks file can brute-force this password using consumer-grade hardware to decrypt stored credentials. | 0% Низкий | 6 дней назад |
Уязвимостей на страницу