Rapid7 Vulnerabilities and Affected Products
Vulnerabilities associated with Metasploit.
Products
Clear product- Velociraptor32 vulnerabilities
- Nexpose17 vulnerabilities
- Insight Agent10 vulnerabilities
- InsightVM9 vulnerabilities
- AppSpider Pro6 vulnerabilities
- Metasploit Framework6 vulnerabilities
- Metasploit Pro6 vulnerabilities
- Metasploit4 vulnerabilities
- InsightCloudSec3 vulnerabilities
- InsightConnect Sed Plugin3 vulnerabilities
- AppSpider2 vulnerabilities
- Insight Platform2 vulnerabilities
- Insight Collector1 vulnerability
- InsightAppSec1 vulnerability
- InsightConnect AWK Plugin1 vulnerability
- InsightConnect Compression Plugin1 vulnerability
- InsightConnect Finger Plugin1 vulnerability
- InsightConnect Markdown Plugin1 vulnerability
- InsightConnect Ping Plugin1 vulnerability
- InsightConnect RPM Plugin1 vulnerability
- InsightConnect SQLmap Plugin1 vulnerability
- InsightConnect Tcpdump Plugin1 vulnerability
- InsightConnect TR Plugin1 vulnerability
- InsightConnect Traceroute Plugin1 vulnerability
- InsightVM Virtual Appliance1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-7384HIGH | Client-Side Command Injection in Rapid7 MetasploitRapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victim's machine. CWE-77Oct 29, 2020 | CVSS7.0v3.1 | EPSS30.5% | PoCs4 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-5231HIGH | All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi CommandDispatcher.cmd_download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance. CWE-22Mar 2, 2017 | CVSS7.1v3.0 | EPSS1.22% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-5229HIGH | All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter extapi Clipboard.parse_dump() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance. CWE-22Mar 2, 2017 | CVSS7.1v3.0 | EPSS1.22% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-5228HIGH | All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi Dir.download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary directory on the Metasploit console with the permissions of the running Metasploit instance. CWE-22Mar 2, 2017 | CVSS7.1v3.0 | EPSS1.22% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |