CVE-2023-28656
published 2023-05-03CVE-2023-28656: NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment. Note: Software…
PriorityP346high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.53%
41.1th percentile
NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | nginx_api_connectivity_manager | — | — |
| f5 | nginx_api_connectivity_manager | >= 1.0.0 < 1.5.0 | 1.5.0 |
| f5 | nginx_instance_manager | — | — |
| f5 | nginx_instance_manager | >= 2.0.0 < 2.9.0 | 2.9.0 |
| f5 | nginx_security_monitoring | — | — |
| f5 | nginx_security_monitoring | >= 1.0.0 < 1.3.0 | 1.3.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
F5
CVE-2023-28656: NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their a...
vendor_f5·2023-05-03·CVSS 8.1
CVE-2023-28656 [HIGH] CWE-639 CVE-2023-28656: NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their a...
CVE-2023-28656: NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their a...
NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Products: Nginx Api Connectivity Manager, Nginx Instance Manager, Nginx Security Monitoring
Affected Versions: 1.0.0 - 1.3.0; 1.0.0 - 1.5.0; 2.0.0 - 2.9.0
F5 Advisory Articles: K000133417
F5 References: https://my.f5.com/manage/s/article/K000133417
GHSA
GHSA-gjg3-3x79-mxh4: NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment
ghsa_unreviewed·2023-07-06
CVE-2023-28656 [HIGH] CWE-639 GHSA-gjg3-3x79-mxh4: NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment
NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-05-03
Published