CVE-2017-5264
high
CVSS v3
8.8
CVSS v2
6.8
VIR risk
8.8
Description
Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web application, and are susceptible to a cross-site request forgery (CSRF) attack.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@rapid7.com — https://help.rapid7.com/nexpose/en-us/release-notes/archive/2017/12/#6.4.66
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| rapid7 | nexpose | {"endExcluding":"6.4.66"} | 6.4.66 |
References
- http://www.securityfocus.com/bid/102208
- https://help.rapid7.com/nexpose/en-us/release-notes/archive/2017/12/#6.4.66
- https://www.exploit-db.com/exploits/43911/
- http://www.securityfocus.com/bid/102208
- https://help.rapid7.com/nexpose/en-us/release-notes/archive/2017/12/#6.4.66
- https://www.exploit-db.com/exploits/43911/
CWEs
CWE-352
Verify integrity in audit chain (admin only). AS-IS.