CVE-2017-5242

Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017 contain identical SSH host keys. Normally, a unique SSH host key should be generated the first time a virtual appliance boots.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rapid7:insightvm:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:27

Type Values Removed Values Added
Summary
  • (es) Los dispositivos virtuales Nexpose e InsightVM descargados entre el 5 de abril de 2017 y el 3 de mayo de 2017 contienen claves de host SSH idénticas. Normalmente, se debe generar una clave de host SSH única la primera vez que se inicia un dispositivo virtual.
References () https://www.rapid7.com/blog/post/2017/05/17/rapid7-nexpose-virtual-appliance-duplicate-ssh-host-key-cve-2017-5242/ - Mitigation, Vendor Advisory () https://www.rapid7.com/blog/post/2017/05/17/rapid7-nexpose-virtual-appliance-duplicate-ssh-host-key-cve-2017-5242/ - Mitigation, Vendor Advisory

Information

Published : 2023-01-12 22:15

Updated : 2024-11-21 03:27


NVD link : CVE-2017-5242

Mitre link : CVE-2017-5242

CVE.ORG link : CVE-2017-5242


JSON object : View

Products Affected

rapid7

  • insightvm
CWE
CWE-321

Use of Hard-coded Cryptographic Key

CWE-330

Use of Insufficiently Random Values