VulnerabilityModified
CVE-2020-5865
In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, making the communicated data vulnerable to interception via man-in-the-middle (MiTM) attacks.
MEDIUM 4.8EPSS 0.40%
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, making the communicated data vulnerable to interception via man-in-the-middle (MiTM) attacks.
- CVSS 3.1
- 4.8 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.40% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-319
- Affected
- f5/nginx controller · netapp/cloud backup
- Source
- f5sirt@f5.com
References
- https://security.netapp.com/advisory/ntap-20200430-0005/Third Party Advisory
- https://support.f5.com/csp/article/K21009022Vendor Advisory
- https://security.netapp.com/advisory/ntap-20200430-0005/Third Party Advisory
- https://support.f5.com/csp/article/K21009022Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.