CVE-2019-5642 is a low-severity vulnerability affecting Rapid7 Metasploit Pro versions 4.16.0-2019081901 and earlier. The vulnerability, categorized as CWE-732 (Improper Permissions), results from the server.key being installed with world-readable permissions. This allows local users on the same system to potentially intercept private communications to the Metasploit Pro web interface. The CVSS score is 3.3 (Low), indicating a local attack vector with low complexity and impact limited to confidentiality. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.16.0CPE matchmatch criteria | cpe:2.3:a:rapid7:metasploit:*:*:*:*:pro:*:*:* | ||
4.16.0CPE matchmatch criteria | cpe:2.3:a:rapid7:metasploit:4.16.0:-:*:*:pro:*:*:* | ||
4.16.0CPE matchmatch criteria | cpe:2.3:a:rapid7:metasploit:4.16.0:20190722:*:*:pro:*:*:* | ||
4.16.0CPE matchmatch criteria | cpe:2.3:a:rapid7:metasploit:4.16.0:20190805:*:*:pro:*:*:* | ||
4.16.0CPE matchmatch criteria | cpe:2.3:a:rapid7:metasploit:4.16.0:2019081901:*:*:pro:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.