Vulnerabilities > Rapid7 > Metasploit > High

DATE CVE VULNERABILITY TITLE RISK
2021-04-23 CVE-2020-7385 Deserialization of Untrusted Data vulnerability in Rapid7 Metasploit
By launching the drb_remote_codeexec exploit, a Metasploit Framework user will inadvertently expose Metasploit to the same deserialization issue that is exploited by that module, due to the reliance on the vulnerable Distributed Ruby class functions.
network
low complexity
rapid7 CWE-502
8.8
2020-10-29 CVE-2020-7384 Command Injection vulnerability in Rapid7 Metasploit
Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victim's machine.
local
low complexity
rapid7 CWE-77
7.8
2020-09-01 CVE-2019-5645 Resource Exhaustion vulnerability in Rapid7 Metasploit
By sending a specially crafted HTTP GET request to a listening Rapid7 Metasploit HTTP handler, an attacker can register an arbitrary regular expression.
network
low complexity
rapid7 CWE-400
7.5
2020-08-24 CVE-2020-7377 Path Traversal vulnerability in Rapid7 Metasploit
The Metasploit Framework module "auxiliary/admin/http/telpho10_credential_dump" module is affected by a relative path traversal vulnerability in the untar method which can be exploited to write arbitrary files to arbitrary locations on the host file system when the module is run on a malicious HTTP server.
network
low complexity
rapid7 CWE-22
7.5
2020-04-22 CVE-2020-7350 OS Command Injection vulnerability in Rapid7 Metasploit
Rapid7 Metasploit Framework versions before 5.0.85 suffers from an instance of CWE-78: OS Command Injection, wherein the libnotify plugin accepts untrusted user-supplied data via a remote computer's hostname or service name.
local
low complexity
rapid7 CWE-78
7.8
2019-04-30 CVE-2019-5624 Path Traversal vulnerability in Rapid7 Metasploit
Rapid7 Metasploit Framework suffers from an instance of CWE-22, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in the Zip import function of Metasploit.
local
low complexity
rapid7 CWE-22
7.3
2017-03-02 CVE-2017-5235 Untrusted Search Path vulnerability in Rapid7 Metasploit 4.11.7/4.12.40/4.13.0
Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.
local
low complexity
rapid7 CWE-426
7.8
2017-03-02 CVE-2017-5231 Path Traversal vulnerability in Rapid7 Metasploit
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi CommandDispatcher.cmd_download() function.
network
high complexity
rapid7 CWE-22
7.1
2017-03-02 CVE-2017-5229 Path Traversal vulnerability in Rapid7 Metasploit
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter extapi Clipboard.parse_dump() function.
network
high complexity
rapid7 CWE-22
7.1
2017-03-02 CVE-2017-5228 Path Traversal vulnerability in Rapid7 Metasploit
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi Dir.download() function.
network
high complexity
rapid7 CWE-22
7.1