Rapid7 Nexpose Update Validation Issue
CVE-2022-4261

4.4MEDIUM

Key Information:

Vendor

Rapid7

Vendor
CVE Published:
8 December 2022

What is CVE-2022-4261?

Rapid7 Nexpose and InsightVM versions prior to 6.6.172 failed to reliably validate the authenticity of update contents. This failure could allow an attacker to provide a malicious update and alter the functionality of Rapid7 Nexpose. The attacker would need some pre-existing mechanism to provide a malicious update, either through a social engineering effort, privileged access to replace downloaded updates in transit, or by performing an Attacker-in-the-Middle attack on the update service itself.

Affected Version(s)

InsightVM 0 <= 6.6.171

Nexpose 0 <= 6.6.171

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

Credit

Emmett Kelly, Rapid7 Principal Software Engineer
.