Show filters
1 Total Results
Displaying 1-1 of 1
Sort by:
Attacker Value
Very Low

Metasploit Pro 4.16 and earlier install the web server SSL server.key as local-…

Disclosure Date: November 06, 2019 (last updated October 06, 2023)
Rapid7 Metasploit Pro version 4.16.0-2019081901 and prior suffers from an instance of CWE-732, wherein the unique server.key is written to the file system during installation with world-readable permissions. This can allow other users of the same system where Metasploit Pro is installed to intercept otherwise private communications to the Metasploit Pro web interface.