Directory Traversal Vulnerability in Rapid7 Metasploit
CVE-2017-5231

7.1HIGH

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
2 March 2017

What is CVE-2017-5231?

A directory traversal vulnerability has been identified in Rapid7 Metasploit affecting all editions before version 4.13.0-2017020701. This issue resides in the Meterpreter stdapi CommandDispatcher.cmd_download() function, enabling attackers to exploit specially-crafted Meterpreter builds. Successful exploitation allows unauthorized file write operations to arbitrary directories on the Metasploit console, which can compromise the security integrity of the system.

Affected Version(s)

Metasploit All versions prior to version 4.13.0-2017020701

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2017-5231 : Directory Traversal Vulnerability in Rapid7 Metasploit