Skip to main content

Vendor/product archive

rapid7 / insightvm CVEs

Beta · best-effort

8 CVEs tagged to rapid7 / insightvm0 Critical, 1 High, 5 Medium, 2 Low, 0 Unrated.

CVE-2024-6504

Published Jul 18, 2024

Rapid7 InsightVM Console versions below 6.6.260 suffer from a protection mechanism failure whereby an attacker with network access to the InsightVM Console can cause it to overloa…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2745

Published Apr 2, 2024

Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the U…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-3844

Published Mar 24, 2023

Rapid7 InsightVM suffers from insufficient session expiration when an administrator performs a security relevant edit on an existing, logged on user. For example, if a user's pass…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0681

Published Mar 20, 2023

Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to a site of the attacker’s choic…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5242

Published Jan 12, 2023

Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017 contain identical SSH host keys. Normally, a unique SSH host key should be generated…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-4261

Published Dec 8, 2022

Rapid7 Nexpose and InsightVM versions prior to 6.6.172 failed to reliably validate the authenticity of update contents. This failure could allow an attacker to provide a malicious…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5641

Published Sep 21, 2022

Rapid7 InsightVM suffers from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the Inspect Element browser feature t…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-5615

Published Apr 9, 2019

Users with Site-level permissions can access files containing the username-encrypted passwords of Security Console Global Administrators and clear-text passwords for restoring bac…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1