cbcvebase.
CVE-2023-28656
published 2023-05-03

CVE-2023-28656: NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment. Note: Software…

PriorityP346high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.53%
41.1th percentile
NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected

6 ranges
VendorProductVersion rangeFixed in
f5nginx_api_connectivity_manager
f5nginx_api_connectivity_manager>= 1.0.0 < 1.5.01.5.0
f5nginx_instance_manager
f5nginx_instance_manager>= 2.0.0 < 2.9.02.9.0
f5nginx_security_monitoring
f5nginx_security_monitoring>= 1.0.0 < 1.3.01.3.0
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.