CVE-2022-35241Uncontrolled Resource Consumption in F5 Nginx Instance Manager

Severity
6.5MEDIUMNVD
EPSS
0.7%
top 29.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 4
Latest updateJun 30

Description

In versions 2.x before 2.3.1 and all versions of 1.x, when NGINX Instance Manager is in use, undisclosed requests can cause an increase in disk resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5f5/nginx_instance_manager2.x2.3.1+1
NVDf5/nginx_instance_manager2.0.02.3.1+1

🔴Vulnerability Details

3
OSV
composer vulnerabilities2025-06-30
GHSA
GHSA-cxjf-pr27-7q48: In versions 22022-08-05
CVEList
NGINX Instance Manager vulnerability CVE-2022-352412022-08-04

📋Vendor Advisories

1
F5
CVE-2022-35241: In versions 22022-08-04
CVE-2022-35241 — Uncontrolled Resource Consumption | cvebase