PT-2019-17782 · Rapid7 · Rapid7 Insightvm

Published

2019-04-09

·

Updated

2020-10-16

·

CVE-2019-5615

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Rapid7 InsightVM versions 6.5.11 through 6.5.49
Description This issue allows users with Site-level permissions to access sensitive files containing encrypted passwords of Security Console Global Administrators and clear-text passwords for backup restoration, along with the password salt. Although valid credentials are needed to access these files, malicious users could still attempt to decrypt the credentials and escalate privileges with additional effort.
Recommendations For Rapid7 InsightVM versions 6.5.11 through 6.5.49, consider restricting access to the sensitive files containing encrypted administrator passwords and clear-text backup passwords to minimize the risk of exploitation. As a temporary workaround, limit the privileges of users with Site-level permissions until a fix is available.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-5615

Affected Products

Rapid7 Insightvm