← Back

CVE-2017-5243

nvd nist
Published: Jun 6, 2017Modified: May 13, 2026

JSON object

Loading...
8.5
Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 6.0
Source: NVD

Description

The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key exchange and other important functions. As a result, it falls back to allowing ALL algorithms supported by the relevant version of OpenSSH and makes the installations vulnerable to a range of MITM, downgrade, and decryption attacks.

Affected (1)

Products: Rapid7: Nexpose
1 product
Nexpose
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 6.4.40

Timeline

No history available yet.