CVE-2020-5864

Severity
7.4HIGH
EPSS
0.4%
top 37.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 23
Latest updateMay 24

Description

In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS verification by default.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 2.2 | Impact: 5.2

Affected Packages2 packages

CVEListV5nginx_controller< 3.2.0
NVDf5/nginx_controller3.0.03.3.0+2

🔴Vulnerability Details

2
GHSA
GHSA-gr6m-w52c-x634: In versions of NGINX Controller prior to 32022-05-24
CVEList
CVE-2020-5864: In versions of NGINX Controller prior to 32020-04-23

📋Vendor Advisories

1
F5
CVE-2020-5864: In versions of NGINX Controller prior to 32020-04-23
CVE-2020-5864 (HIGH CVSS 7.4) | In versions of NGINX Controller pri | cvebase.io