NGINX Controller TLS Certificate Verification Issues by F5 Networks
CVE-2020-5909

5.4MEDIUM

Key Information:

Vendor
F5
Vendor
CVE Published:
2 July 2020

Summary

In specific versions of NGINX Controller, there is a vulnerability that allows users to execute commands through the user interface to fetch an agent installer without proper verification of the server's TLS certificate. This issue may lead to potential security risks as it exposes systems to man-in-the-middle attacks and other security threats, allowing attackers to intercept communication if the certificate is not verified correctly. Organizations using affected versions should take immediate steps to update their systems and ensure secure configurations.

Affected Version(s)

NGINX Controller 3.0.0-3.5.0, 2.0.0-2.9.0, 1.0.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.