Rapid7 Nexpose versions prior to 6.6.172 failed to...
Moderate severity
Unreviewed
Published
Dec 8, 2022
to the GitHub Advisory Database
•
Updated Jan 28, 2023
Description
Published by the National Vulnerability Database
Dec 8, 2022
Published to the GitHub Advisory Database
Dec 8, 2022
Last updated
Jan 28, 2023
Rapid7 Nexpose versions prior to 6.6.172 failed to reliably validate the authenticity of update contents. This failure could allow an attacker to provide a malicious update and alter the functionality of Rapid7 Nexpose. The attacker would need some pre-existing mechanism to provide a malicious update, either through a social engineering effort, privileged access to replace downloaded updates in transit, or by performing an Attacker-in-the-Middle attack on the update service itself.
References