6.5
CVSSv3

CVE-2020-7382

Published: 03/09/2020 Updated: 11/09/2020
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
CVSS v3 Base Score: 6.5 | Impact Score: 5.9 | Exploitability Score: 0.6
VMScore: 392
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Rapid7 Nexpose installer version before 6.6.40 contains an Unquoted Search Path which may allow an attacker on the local machine to insert an arbitrary file into the executable path. This issue affects: Rapid7 Nexpose versions before 6.6.40.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rapid7 nexpose