nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability in NSE script http-fetch that can result in file overwrite as the user is running it. This attack appears to be exploitable via a victim that runs NSE script http-fetch against a malicious web site. This vulnerability appears to have been fixed in 7.7.
CVSS Details
- CVSS 3.1 Base Score: 5.7
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade nmap | Jul 30, 2024 | Apr 18, 2018 |
| Oracle Solaris | — | Upgrade diagnostic/nmap to version 7.70-11.4.3.0.1.4.0 on Solaris 11.4Upgrade diagnostic/nmap/zenmap to version 7.70-11.4.3.0.1.4.0 on Solaris 11.4 | Nov 19, 2018 | Apr 18, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Apr 18, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub