CVE-2012-6494: RAPID7 Nexpose

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

Rapid7 Nexpose before 5.5.4 contains a session hijacking vulnerability which allows remote attackers to capture a user's session and gain unauthorized access.

Affected products

  • RAPID7 Nexpose: before 5.5.4 (fixed in 5.5.4)

Published 2020-01-25. Last modified 2026-06-16.