CVE-2022-3913
Last modified
CVE-2022-3913 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Rapid7 Nexpose and InsightVM versions 6.6.82 through 6.6.177 fail to validate the certificate of the update server when downloading updates. This failure could allow an attacker in a privileged position on the network to provide their own HTTPS endpoint, or intercept communications to the legitimate endpoint. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
Rapid7 Nexpose and InsightVM versions 6.6.82 through 6.6.177 fail to validate the certificate of the update server when downloading updates. This failure could allow an attacker in a privileged position on the network to provide their own HTTPS endpoint, or intercept communications to the legitimate endpoint. The attacker would need some pre-existing access to at least one node on the network path between the Rapid7-controlled update server and the Nexpose/InsightVM application, and the ability to either spoof the update server's FQDN or redirect legitimate traffic to the attacker's server in order to exploit this vulnerability. Note that even in this scenario, an attacker could not normally replace an update package with a malicious package, since the update process validates a separate, code-signing certificate, distinct from the HTTPS certificate used for communication. This issue was resolved on February 1, 2023 in update 6.6.178 of Nexpose and InsightVM.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rapid7 | Nexpose | >= 6.6.82, < 6.6.178 |
References
- https://docs.rapid7.com/release-notes/nexpose/20230201/Release Notes, Vendor Advisory
- https://docs.rapid7.com/release-notes/nexpose/20230201/Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3913?
How severe is CVE-2022-3913?
How do I fix CVE-2022-3913?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-39124In sensor driver, there is a possible out of bounds write du…5.5
- CVE-2022-39125In sensor driver, there is a possible out of bounds write du…5.5
- CVE-2022-39126In sensor driver, there is a possible out of bounds write du…5.5
- CVE-2022-39127In sensor driver, there is a possible out of bounds write du…5.5
- CVE-2022-39128In sensor driver, there is a possible out of bounds write du…5.5
- CVE-2022-39129In face detect driver, there is a possible out of bounds wri…5.5
- CVE-2022-39130In face detect driver, there is a possible out of bounds wri…5.5
- CVE-2022-39131In camera driver, there is a possible memory corruption due …5.5
- CVE-2022-39132In camera driver, there is a possible out of bounds write du…5.5
- CVE-2022-39133In wlan driver, there is a possible missing bounds check, Th…5.5
- CVE-2022-39134In audio driver, there is a use after free due to a race con…4.7
- CVE-2022-39135Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NO…9.8
Are you affected by CVE-2022-3913?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
