Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-5645

By sending a specially crafted HTTP GET request to a listening Rapid7 Metasploit HTTP handler, an attacker can register an arbitrary regular expression. When evaluated, this malicious handler can either prevent new HTTP handler sessions from being established, or cause a resource exhaustion on the Metasploit server.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.879
EPSS Ranking 99.4%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2019-5645


Contact Us

Shodan ® - All rights reserved