PT-2020-2706 · Rapid7 · Rapid7 Metasploit Framework+1
Pastaoficialo
·
Published
2020-03-04
·
Updated
2020-06-05
·
CVE-2020-7350
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Rapid7 Metasploit Framework versions prior to 5.0.85
Description
The issue arises from the libnotify plugin accepting untrusted user-supplied data via a remote computer's hostname or service name, leading to an instance of OS Command Injection. An attacker can create a specially-crafted hostname or service name to trigger a command injection on the operator's terminal. This vulnerability cannot be triggered through a normal scan operation and requires the attacker to supply a file that is processed with the db import command.
Recommendations
For Rapid7 Metasploit Framework versions prior to 5.0.85, update to version 5.0.85 or later to resolve the issue.
As a temporary workaround, consider restricting the use of the libnotify plugin until a patch is available.
Avoid using the db import command with untrusted files until the issue is resolved.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rapid7 Metasploit Framework
Libnotify