Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ken Mizota

Researcher fromRapid7
#36205of 56,330
7.7Total CVSS
Vulnerabilities · 1
PT-2023-10639
7.7
2023-01-12
Rapid7 · Nexpose · CVE-2017-5242
**Name of the Vulnerable Software and Affected Versions** Nexpose virtual appliances versions downloaded between April 5th, 2017 and May 3rd, 2017 InsightVM virtual appliances versions downloaded between April 5th, 2017 and May 3rd, 2017 **Description** The issue concerns Nexpose and InsightVM virtual appliances that were downloaded between April 5th, 2017 and May 3rd, 2017. These appliances contain identical SSH host keys, which is unusual because a unique SSH host key should be generated the first time a virtual appliance boots. **Recommendations** For Nexpose virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017, consider regenerating the SSH host key to ensure uniqueness. For InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017, consider regenerating the SSH host key to ensure uniqueness. As a temporary workaround, restrict access to the SSH service until a unique SSH host key can be generated.