SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-4261

Rapid7 Nexpose and InsightVM versions prior to 6.6.172 failed to reliably validate the authenticity of update contents.

MEDIUM 6.5EPSS 0.31%

Does this matter?

Lower severity and a low EPSS score (0.31%). Track it; it rarely justifies an emergency change on its own.

Description

Rapid7 Nexpose and InsightVM versions prior to 6.6.172 failed to reliably validate the authenticity of update contents. This failure could allow an attacker to provide a malicious update and alter the functionality of Rapid7 Nexpose. The attacker would need some pre-existing mechanism to provide a malicious update, either through a social engineering effort, privileged access to replace downloaded updates in transit, or by performing an Attacker-in-the-Middle attack on the update service itself.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
0.31% probability · 23th percentile
CISA KEV
Not listed
Weakness
CWE-494
Affected
rapid7/insightvm · rapid7/nexpose
Source
cve@rapid7.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.