vendor:
Nexpose Security Console
by:
Saud Alenazi
6.1
CVSS
HIGH
Unquoted Service Path
428
CWE
Product Name: Nexpose Security Console
Affected Version From: 6.6.0240
Affected Version To: 6.6.0240
Patch Exists: NO
Related CWE: CVE-2024-XXXX (Not provided in the text)
CPE: rapid7:nexpose:6.6.240
Other Scripts:
https://www.infosecmatter.com/why-your-exploit-completed-but-no-session-was-created-try-these-fixes/, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/smb/ms17_010_eternalblue, https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/scanner/smb/smb_enumshares, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/unix/webapp/drupal_restws_unserialize, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/unix/webapp/drupal_drupalgeddon2, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/unix/webapp/thinkphp_rce, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/local/nscp_pe, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/linux/http/fortinet_authentication_bypass_cve_2022_40684, https://www.infosecmatter.com/top-25-penetration-testing-skills-and-competencies-detailed/, https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/gather/cloud_lookup
Platforms Tested: Windows 10 x64
2024
Rapid7 Nexpose Unquoted Service Path Vulnerability
The Rapid7 Nexpose Security Console version 6.6.240 on Windows 10 x64 is vulnerable to an unquoted service path issue. By inserting malicious code into the system root path, an attacker could potentially execute the code with elevated privileges during application startup or reboot.
Mitigation:
To mitigate this vulnerability, users should ensure that all service paths are quoted correctly. Regular security checks and monitoring for unauthorized system changes can also help prevent exploitation.