PT-2020-2706 · Rapid7 · Rapid7 Metasploit Framework+1

Pastaoficialo

·

Published

2020-03-04

·

Updated

2020-06-05

·

CVE-2020-7350

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rapid7 Metasploit Framework versions prior to 5.0.85
Description The issue arises from the libnotify plugin accepting untrusted user-supplied data via a remote computer's hostname or service name, leading to an instance of OS Command Injection. An attacker can create a specially-crafted hostname or service name to trigger a command injection on the operator's terminal. This vulnerability cannot be triggered through a normal scan operation and requires the attacker to supply a file that is processed with the db import command.
Recommendations For Rapid7 Metasploit Framework versions prior to 5.0.85, update to version 5.0.85 or later to resolve the issue. As a temporary workaround, consider restricting the use of the libnotify plugin until a patch is available. Avoid using the db import command with untrusted files until the issue is resolved.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02782
CVE-2020-7350

Affected Products

Rapid7 Metasploit Framework
Libnotify