CVE-2020-5910
published 2020-07-02CVE-2020-5910: In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.15%
63.3th percentile
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | nginx_controller | — | — |
| f5 | nginx_controller | — | — |
| f5 | nginx_controller | — | — |
| f5 | nginx_controller | 2.0.0 – 2.9.0 | — |
| f5 | nginx_controller | 3.0.0 – 3.5.0 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2020-5910: In versions 3
vendor_f5·2020-07-02·CVSS 7.5
CVE-2020-5910 [HIGH] CWE-306 CVE-2020-5910: In versions 3
CVE-2020-5910: In versions 3
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.
Affected Products: NGINX Controller
Affected Versions: 1.0.1; 2.0.0 - 2.9.0; 3.0.0 - 3.5.0
F5 Advisory Articles: K59209532
F5 References: https://support.f5.com/csp/article/K59209532
GHSA
GHSA-3h32-r78h-g4px: In versions 3
ghsa_unreviewed·2022-05-24
CVE-2020-5910 [MEDIUM] CWE-287 GHSA-3h32-r78h-g4px: In versions 3
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-07-02
Published