SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-5863

In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unprivileged user accounts.

HIGH 8.6EPSS 1.15%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.15%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unprivileged user accounts. The user which is created is only able to upload a new license to the system but cannot view or modify any other components of the system.

CVSS 3.1
8.6 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
EPSS
1.15% probability · 65th percentile
CISA KEV
Not listed
Affected
f5/nginx controller · netapp/cloud backup
Source
f5sirt@f5.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.