CVE-2023-28724

Severity
7.1HIGH
EPSS
0.1%
top 74.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 3
Latest updateJul 6

Description

NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance Manager and NGINX API Connectivity Manager. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 1.8 | Impact: 5.2

Affected Packages6 packages

CVEListV5f5/nginx_instance_manager2.0.02.9.0+1
NVDf5/nginx_instance_manager2.0.02.9.0
CVEListV5f5/nginx_api_connectivity_manager1.0.01.5.0
CVEListV5f5/nginx_security_monitoring1.0.01.3.0

🔴Vulnerability Details

2
GHSA
GHSA-9mcp-v29j-j4hp: NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance Ma2023-07-06
CVEList
NGINX Management Suite vulnerability2023-05-03

📋Vendor Advisories

1
F5
CVE-2023-28724: NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sen...2023-05-03
CVE-2023-28724 (HIGH CVSS 7.1) | NGINX Management Suite default file | cvebase.io