CVE Database
/

CVE-2017-5242

Back to search

CVE-2017-5242

Published: Jan 12, 2023

Modified: Apr 8, 2025

PUBLISHED

Description

Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017 contain identical SSH host keys. Normally, a unique SSH host key should be generated the first time a virtual appliance boots.

VendorProductVersions

Rapid7

Nexpose Virtual Appliance

affected
2017.04.05 - < 2017.04.05*
affected
2017.05.03 - <= 2017.05.03

Rapid7

InsightVM Virtual Appliance

affected
2017.04.05 - < 2017.04.05*
affected
2017.05.03 - <= 2017.05.03

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now