CVE-2020-5910
Last modified
CVE-2020-5910 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.. EPSS estimates a 1.15% chance of exploitation in the next 30 days.
Description
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| F5 | Nginx Controller | >= 2.0.0, <= 2.9.0 |
| F5 | Nginx Controller | >= 3.0.0, <= 3.5.0 |
| F5 | Nginx Controller | 1.0.1 |
References
- https://support.f5.com/csp/article/K59209532Vendor Advisory
- https://support.f5.com/csp/article/K59209532Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-5910?
How severe is CVE-2020-5910?
How do I fix CVE-2020-5910?
Are you affected by CVE-2020-5910?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
