CVE detail
CVE-2019-5642 — CVE-2019-5642
Published 2019-11-06 · Modified 2026-06-17 · Vendor rapid7 · Product metasploit · Source nvd
LOW
severity
CVSS-derived band
0.0031
EPSS probability
exploitation probability, 30d
24.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Rapid7 Metasploit Pro version 4.16.0-2019081901 and prior suffers from an instance of CWE-732, wherein the unique server.key is written to the file system during installation with world-readable permissions. This can allow other users of the same system where Metasploit Pro is installed to intercept otherwise private communications to the Metasploit Pro web interface.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References