First published: Thu Jan 12 2023(Updated: )
Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017 contain identical SSH host keys. Normally, a unique SSH host key should be generated the first time a virtual appliance boots.
Credit: cve@rapid7.con
Affected Software | Affected Version | How to fix |
---|---|---|
Rapid7 InsightVM | >=2017-04-05<=2017-05-03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5242 is a vulnerability found in Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017, and May 3rd, 2017, which contain identical SSH host keys.
CVE-2017-5242 has a severity value of 7.7, which is considered high.
CVE-2017-5242 impacts Rapid7 InsightVM virtual appliances downloaded between April 5th, 2017, and May 3rd, 2017, by having identical SSH host keys.
To fix the CVE-2017-5242 vulnerability, you need to download and install the updated version of Nexpose or InsightVM virtual appliances that generate unique SSH host keys.
You can find more information about CVE-2017-5242 on the Rapid7 blog at https://www.rapid7.com/blog/post/2017/05/17/rapid7-nexpose-virtual-appliance-duplicate-ssh-host-key-cve-2017-5242/