CVE-2020-7377: Rapid7 Metasploit Framework Relative Path Traversal in telpho10_credential_dump module
The Metasploit Framework module "auxiliary/admin/http/telpho10credentialdump" module is affected by a relative path traversal vulnerability in the untar method which can be exploited to write arbitrary files to arbitrary locations on the host file system when the module is run on a malicious HTTP server.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-7377?
The severity of CVE-2020-7377 is high with a CVSS score of 7.5.
What module is affected by CVE-2020-7377?
The module affected by CVE-2020-7377 is 'auxiliary/admin/http/telpho10_credential_dump' in the Metasploit Framework.
How does the vulnerability in CVE-2020-7377 work?
The vulnerability in CVE-2020-7377 is a relative path traversal vulnerability that allows an attacker to write arbitrary files to arbitrary locations on the host file system when the 'auxiliary/admin/http/telpho10_credential_dump' module is run on a malicious HTTP server.
How can I fix CVE-2020-7377?
Updating the affected software to a version higher than 6.0.3 or applying the necessary patches provided by Rapid7 Metasploit can fix CVE-2020-7377.
Where can I find more information about CVE-2020-7377?
You can find more information about CVE-2020-7377 on the GitHub page for Rapid7 Metasploit Framework: https://github.com/rapid7/metasploit-framework/issues/14015.