NGINX Controller TLS Certificate Verification Issues by F5 Networks
CVE-2020-5909
5.4MEDIUM
Summary
In specific versions of NGINX Controller, there is a vulnerability that allows users to execute commands through the user interface to fetch an agent installer without proper verification of the server's TLS certificate. This issue may lead to potential security risks as it exposes systems to man-in-the-middle attacks and other security threats, allowing attackers to intercept communication if the certificate is not verified correctly. Organizations using affected versions should take immediate steps to update their systems and ensure secure configurations.
Affected Version(s)
NGINX Controller 3.0.0-3.5.0, 2.0.0-2.9.0, 1.0.1
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved