CVE-2020-5865
published 2020-04-23CVE-2020-5865: In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, making the…
PriorityP421medium4.8CVSS 3.1
AVNACHPRNUINSUCLILAN
EPSS
0.39%
31.1th percentile
In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, making the communicated data vulnerable to interception via man-in-the-middle (MiTM) attacks.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | nginx_controller | < 3.3.0 | 3.3.0 |
| f5 | nginx_controller | — | — |
| f5 | nginx_controller | — | — |
| f5 | nginx_controller | 2.0.0 – 2.9.0 | — |
| f5 | nginx_controller | >= 3.0.0 < 3.3.0 | 3.3.0 |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-83x8-frp9-8943: In versions prior to 3
ghsa_unreviewed·2022-05-24
CVE-2020-5865 [MEDIUM] CWE-200 GHSA-83x8-frp9-8943: In versions prior to 3
In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, making the communicated data vulnerable to interception via man-in-the-middle (MiTM) attacks.
F5
CVE-2020-5865: In versions prior to 3
vendor_f5·2020-04-23·CVSS 4.8
CVE-2020-5865 [MEDIUM] CWE-319 CVE-2020-5865: In versions prior to 3
CVE-2020-5865: In versions prior to 3
In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, making the communicated data vulnerable to interception via man-in-the-middle (MiTM) attacks.
Affected Products: NGINX Controller
Affected Versions: 1.0.1; 2.0.0 - 2.9.0; 3.0.0 - 3.3.0
F5 Advisory Articles: K21009022
F5 References: https://support.f5.com/csp/article/K21009022
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-04-23
Published