CVE-2022-4261

Rapid7 Nexpose and InsightVM versions prior to 6.6.172 failed to reliably validate the authenticity of update contents. This failure could allow an attacker to provide a malicious update and alter the functionality of Rapid7 Nexpose. The attacker would need some pre-existing mechanism to provide a malicious update, either through a social engineering effort, privileged access to replace downloaded updates in transit, or by performing an Attacker-in-the-Middle attack on the update service itself.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:rapid7:insightvm:*:*:*:*:*:*:*:*
cpe:2.3:a:rapid7:nexpose:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:57

Type Values Removed Values Added
Summary Rapid7 Nexpose and InsightVM versions prior to 6.6.172 failed to reliably validate the authenticity of update contents. This failure could allow an attacker to provide a malicious update and alter the functionality of Rapid7 Nexpose. The attacker would need some pre-existing mechanism to provide a malicious update, either through a social engineering effort, privileged access to replace downloaded updates in transit, or by performing an Attacker-in-the-Middle attack on the update service itself. Rapid7 Nexpose and InsightVM versions prior to 6.6.172 failed to reliably validate the authenticity of update contents. This failure could allow an attacker to provide a malicious update and alter the functionality of Rapid7 Nexpose. The attacker would need some pre-existing mechanism to provide a malicious update, either through a social engineering effort, privileged access to replace downloaded updates in transit, or by performing an Attacker-in-the-Middle attack on the update service itself.

12 Dec 2022, 17:09

Type Values Removed Values Added
CWE CWE-494
CPE cpe:2.3:a:rapid7:insightvm:*:*:*:*:*:*:*:*
cpe:2.3:a:rapid7:nexpose:*:*:*:*:*:*:*:*
First Time Rapid7
Rapid7 nexpose
Rapid7 insightvm
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References (CONFIRM) https://www.rapid7.com/blog/post/2022/12/7/cve-2022-4261-rapid7-nexpose-update-validation-issue-fixed - (CONFIRM) https://www.rapid7.com/blog/post/2022/12/7/cve-2022-4261-rapid7-nexpose-update-validation-issue-fixed - Exploit, Mitigation, Vendor Advisory
References (CONFIRM) https://docs.rapid7.com/release-notes/insightvm/20221207/ - (CONFIRM) https://docs.rapid7.com/release-notes/insightvm/20221207/ - Release Notes, Vendor Advisory
References (CONFIRM) https://docs.rapid7.com/release-notes/nexpose/20221207/ - (CONFIRM) https://docs.rapid7.com/release-notes/nexpose/20221207/ - Release Notes, Vendor Advisory

08 Dec 2022, 15:15

Type Values Removed Values Added
References
  • (CONFIRM) https://docs.rapid7.com/release-notes/insightvm/20221207/ -
Summary Rapid7 Nexpose versions prior to 6.6.172 failed to reliably validate the authenticity of update contents. This failure could allow an attacker to provide a malicious update and alter the functionality of Rapid7 Nexpose. The attacker would need some pre-existing mechanism to provide a malicious update, either through a social engineering effort, privileged access to replace downloaded updates in transit, or by performing an Attacker-in-the-Middle attack on the update service itself. Rapid7 Nexpose and InsightVM versions prior to 6.6.172 failed to reliably validate the authenticity of update contents. This failure could allow an attacker to provide a malicious update and alter the functionality of Rapid7 Nexpose. The attacker would need some pre-existing mechanism to provide a malicious update, either through a social engineering effort, privileged access to replace downloaded updates in transit, or by performing an Attacker-in-the-Middle attack on the update service itself.

08 Dec 2022, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-08 00:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-4261

Mitre link : CVE-2022-4261

CVE.ORG link : CVE-2022-4261


JSON object : View

Products Affected

rapid7

  • nexpose
  • insightvm
CWE
CWE-494

Download of Code Without Integrity Check