CVE-2017-5230: High severity Rapid7 Nexpose vulnerability
The Java keystore in all versions and editions of Rapid7 Nexpose prior to 6.4.50 is encrypted with a static password of 'r@p1d7k3y5t0r3' which is not modifiable by the user. The keystore provides storage for saved scan credentials in an otherwise secure location on disk.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rapid7 Nexposeto a version that resolves this vulnerability.Fixed in 6.4.50 - Operational
Update Rapid7 Nexpose to 6.4.50 or later to address the keystore static password issue; then re-save scan credentials as needed so they are stored using the updated keystore behavior.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5230?
CVE-2017-5230 is considered to have a high severity due to the use of a static password for the keystore.
How do I fix CVE-2017-5230?
To fix CVE-2017-5230, upgrade Rapid7 Nexpose to version 6.4.50 or later.
What versions of Rapid7 Nexpose are affected by CVE-2017-5230?
CVE-2017-5230 affects all versions of Rapid7 Nexpose prior to 6.4.50.
What data is compromised by CVE-2017-5230?
CVE-2017-5230 potentially compromises saved scan credentials stored in the Java keystore.
Is the static password in CVE-2017-5230 user-modifiable?
No, the static password used in CVE-2017-5230 is not modifiable by the user.