VulnerabilityModified
CVE-2020-5863
In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unprivileged user accounts.
HIGH 8.6EPSS 1.15%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.15%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unprivileged user accounts. The user which is created is only able to upload a new license to the system but cannot view or modify any other components of the system.
- CVSS 3.1
- 8.6 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
- EPSS
- 1.15% probability · 65th percentile
- CISA KEV
- Not listed
- Affected
- f5/nginx controller · netapp/cloud backup
- Source
- f5sirt@f5.com
References
- https://security.netapp.com/advisory/ntap-20200430-0005/Third Party Advisory
- https://support.f5.com/csp/article/K14631834Vendor Advisory
- https://security.netapp.com/advisory/ntap-20200430-0005/Third Party Advisory
- https://support.f5.com/csp/article/K14631834Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.