CVE-2020-5863

Severity
8.6HIGH
EPSS
1.1%
top 21.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 27
Latest updateMay 24

Description

In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unprivileged user accounts. The user which is created is only able to upload a new license to the system but cannot view or modify any other components of the system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:HExploitability: 3.9 | Impact: 4.7

Affected Packages2 packages

NVDf5/nginx_controller3.0.03.2.0+2
CVEListV5nginx_controller3.0.0-3.1.0, 2.0.0-2.9.0, 1.0.1

🔴Vulnerability Details

2
GHSA
GHSA-92v9-882v-4qfr: In NGINX Controller versions prior to 32022-05-24
CVEList
CVE-2020-5863: In NGINX Controller versions prior to 32020-03-27

📋Vendor Advisories

1
F5
CVE-2020-5863: In NGINX Controller versions prior to 32020-03-27
CVE-2020-5863 (HIGH CVSS 8.6) | In NGINX Controller versions prior | cvebase.io