PT-2019-17782 · Rapid7 · Rapid7 Insightvm
Publicado
2019-04-09
·
Atualizado
2020-10-16
·
CVE-2019-5615
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Rapid7 InsightVM versions 6.5.11 through 6.5.49
Description
This issue allows users with Site-level permissions to access sensitive files containing encrypted passwords of Security Console Global Administrators and clear-text passwords for backup restoration, along with the password salt. Although valid credentials are needed to access these files, malicious users could still attempt to decrypt the credentials and escalate privileges with additional effort.
Recommendations
For Rapid7 InsightVM versions 6.5.11 through 6.5.49, consider restricting access to the sensitive files containing encrypted administrator passwords and clear-text backup passwords to minimize the risk of exploitation. As a temporary workaround, limit the privileges of users with Site-level permissions until a fix is available.
Correção
Insufficiently Protected Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Rapid7 Insightvm