← Back

CVE-2020-5865

nvd nist
Published: Apr 23, 2020Modified: Nov 21, 2024

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 2.2 / Impact: 2.5
Source: NVD

Description

In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, making the communicated data vulnerable to interception via man-in-the-middle (MiTM) attacks.

Affected (4)

1 product
Nginx Controller
1 product
Cloud Backup
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 2.0.0 to 2.9.0
From 3.0.0 to 3.3.0
Version 1.0.1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (4)

Source: f5sirt@f5.com
Third Party Advisory
Source: f5sirt@f5.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.