VYPR
High severity7.7NVD Advisory· Published Jan 12, 2023· Updated Jun 17, 2026

CVE-2017-5242

CVE-2017-5242

Description

Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017 contain identical SSH host keys. Normally, a unique SSH host key should be generated the first time a virtual appliance boots.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Rapid7/InsightVM2 versions
    cpe:2.3:a:rapid7:insightvm:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:rapid7:insightvm:*:*:*:*:*:*:*:*range: >=2017-04-05,<=2017-05-03
    • (no CPE)
  • Rapid7/Nexposellm-fuzzy
  • Rapid7/InsightVM Virtual Appliancev5
    Range: 2017.04.05
  • Rapid7/Nexpose Virtual Appliancev5
    Range: 2017.04.05

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.