Metasploit

Vendor:

First CVE: Mar 2, 2017 · Active for 9 years

17
Total CVEs
More Total CVEs than 94% of tracked products
3.4
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Metasploit over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 2, 2017
9 years ago
Most Recent CVE
Feb 1, 2023
1,272 days ago

CVE Severity & Scoring

Metasploit17 CVEs
All CVEs352,785 CVEs
LowMediumHighCritical
Attack Vector
Local5 (29.4%)
Network12 (70.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (82.4%)
High3 (17.6%)
Unknown0 (0.0%)
User Interaction
None4 (23.5%)
Unknown0 (0.0%)
Required13 (76.5%)
Privileges Required
Low3 (17.6%)
High1 (5.9%)
None13 (76.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victim's m
Oct 29, 20207.861NOYES
By sending a specially crafted HTTP GET request to a listening Rapid7 Metasploit HTTP handler, an attacker can register an arbitrary regular expression. When evaluated, this malici
Sep 1, 20207.559NOYES
The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.
Oct 6, 20176.533NOYES
Rapid7 Metasploit Framework versions before 5.0.85 suffers from an instance of CWE-78: OS Command Injection, wherein the libnotify plugin accepts untrusted user-supplied data via a
Apr 22, 20207.832NOYES
By launching the drb_remote_codeexec exploit, a Metasploit Framework user will inadvertently expose Metasploit to the same deserialization issue that is exploited by that module, d
Apr 23, 20218.828NONO
Rapid7 Metasploit Framework suffers from an instance of CWE-22, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in the Zip import function of Metaspl
Apr 30, 20197.325NONO
The Metasploit Framework module "post/osx/gather/enum_osx module" is affected by a relative path traversal vulnerability in the get_keychains method which can be exploited to write
Aug 24, 20209.824NONO
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi CommandDispatcher.cmd_download() function
Mar 2, 20177.123NONO
Cross-site Scripting (XSS) vulnerability in the 'notes' field of a discovered scan asset in Rapid7 Metasploit Pro allows an attacker with a specially-crafted network service of a s
Jun 25, 20206.121NONO
Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located
Mar 2, 20177.821NONO

Exploit Exposure

Signals from CVEs in this product scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
17.6% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
11.8% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (17 CVEs).

Media Mentions

Signals from CVEs in this product scope (17 CVEs).

Top CNAs Publishing CVEs For Metasploit

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.17.125.80.9%00
4.16.013.30.3%00