Record summary

CVE-2019-5645 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.

Description

By sending a specially crafted HTTP GET request to a listening Rapid7 Metasploit HTTP handler, an attacker can register an arbitrary regular expression. When evaluated, this malicious handler can either prevent new HTTP handler sessions from being established, or cause a resource exhaustion on the Metasploit server.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List5.0.27 to ≤ 5.0.27affected

Proofs of concept

1

Catalogued exploits

MetasploitMetasploit HTTP(S) handler DoSMetasploit auxiliary PoCby Angelo Seiler, Dreamlab Technologies AG +1 moreNot analyzed1 file

Ruby

Metasploit

PoC details

References

2