github.com
https://github.com/rapid7/metasploit-framework/pull/12433 CVE-2019-5645
HIGH
Rapid7 Metasploit HTTP Handler Denial of Service
Record summary
CVE-2019-5645 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
By sending a specially crafted HTTP GET request to a listening Rapid7 Metasploit HTTP handler, an attacker can register an arbitrary regular expression. When evaluated, this malicious handler can either prevent new HTTP handler sessions from being established, or cause a resource exhaustion on the Metasploit server.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Metasploit FrameworkBrowse Rapid7 / Metasploit Framework | CVE List | 5.0.27 to ≤ 5.0.27 | affected |
Proofs of concept
1Catalogued exploits
MetasploitMetasploit HTTP(S) handler DoSMetasploit auxiliary PoCby Angelo Seiler, Dreamlab Technologies AG +1 moreNot analyzed1 file
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-5645