CVE-2020-7382: Unquoted Path in Rapid7 Nexpose Installer
Rapid7 Nexpose installer version prior to 6.6.40 contains an Unquoted Search Path which may allow an attacker on the local machine to insert an arbitrary file into the executable path. This issue affects: Rapid7 Nexpose versions prior to 6.6.40.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7382?
CVE-2020-7382 is a vulnerability in Rapid7 Nexpose installer versions prior to 6.6.40 that contains an unquoted search path, allowing an attacker to insert an arbitrary file into the executable path.
How does CVE-2020-7382 affect Rapid7 Nexpose?
CVE-2020-7382 affects Rapid7 Nexpose versions prior to 6.6.40.
What is the severity of CVE-2020-7382?
The severity of CVE-2020-7382 is medium with a severity value of 6.5.
How can an attacker exploit CVE-2020-7382?
An attacker on the local machine can exploit CVE-2020-7382 by inserting an arbitrary file into the executable path.
How can I fix CVE-2020-7382?
To fix CVE-2020-7382, update Rapid7 Nexpose installer to version 6.6.40 or later.