cbcvebase.
CVE-2020-5865
published 2020-04-23

CVE-2020-5865: In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, making the…

PriorityP421medium4.8CVSS 3.1
AVNACHPRNUINSUCLILAN
EPSS
0.39%
31.1th percentile
In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, making the communicated data vulnerable to interception via man-in-the-middle (MiTM) attacks.

Affected

5 ranges
VendorProductVersion rangeFixed in
f5nginx_controller< 3.3.03.3.0
f5nginx_controller
f5nginx_controller
f5nginx_controller2.0.0 – 2.9.0
f5nginx_controller>= 3.0.0 < 3.3.03.3.0

CVSS provenance

nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.