Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2022-3913

Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-295 Validación incorrecta de certificados
Fecha de publicación:
01/02/2023
Última modificación:
07/11/2023

Descripción

*** Pendiente de traducción *** Rapid7 Nexpose and InsightVM versions 6.6.82 through 6.6.177 fail to validate the certificate of the update server when downloading updates. This failure could allow an attacker in a privileged position on the network to provide their own HTTPS endpoint, or intercept communications to the legitimate endpoint. The attacker would need some pre-existing access to at least one node on the network path between the Rapid7-controlled update server and the Nexpose/InsightVM application, and the ability to either spoof the update server&amp;#39;s FQDN or redirect legitimate traffic to the attacker&amp;#39;s server in order to exploit this vulnerability. Note that even in this scenario, an attacker could not normally replace an update package with a malicious package, since the update process validates a separate, code-signing certificate, distinct from the HTTPS certificate used for communication. This issue was resolved on February 1, 2023 in update 6.6.178 of Nexpose and InsightVM.<br /> <br /> <br /> <br /> <br />

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:rapid7:nexpose:*:*:*:*:*:*:*:* 6.6.82 (incluyendo) 6.6.178 (excluyendo)