CVE-2020-5863
published 2020-03-27CVE-2020-5863: In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unprivileged user accounts. The…
PriorityP350high8.6CVSS 3.1
AVNACLPRNUINSUCLILAH
EPSS
1.12%
62.4th percentile
In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unprivileged user accounts. The user which is created is only able to upload a new license to the system but cannot view or modify any other components of the system.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | nginx_controller | — | — |
| f5 | nginx_controller | — | — |
| f5 | nginx_controller | — | — |
| f5 | nginx_controller | 2.0.0 – 2.9.0 | — |
| f5 | nginx_controller | >= 3.0.0 < 3.2.0 | 3.2.0 |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-92v9-882v-4qfr: In NGINX Controller versions prior to 3
ghsa_unreviewed·2022-05-24
CVE-2020-5863 [HIGH] CWE-863 GHSA-92v9-882v-4qfr: In NGINX Controller versions prior to 3
In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unprivileged user accounts. The user which is created is only able to upload a new license to the system but cannot view or modify any other components of the system.
F5
CVE-2020-5863: In NGINX Controller versions prior to 3
vendor_f5·2020-03-27·CVSS 8.6
CVE-2020-5863 [HIGH] CVE-2020-5863: In NGINX Controller versions prior to 3
CVE-2020-5863: In NGINX Controller versions prior to 3
In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unprivileged user accounts. The user which is created is only able to upload a new license to the system but cannot view or modify any other components of the system.
Affected Products: NGINX Controller
Affected Versions: 1.0.1; 2.0.0 - 2.9.0; 3.0.0 - 3.2.0
F5 Advisory Articles: K14631834
F5 References: https://support.f5.com/csp/article/K14631834
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-03-27
Published