← Back

CVE-2023-28724

nvd nist
Published: May 3, 2023Modified: Apr 10, 2025

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 1.8 / Impact: 5.2
Source: NVD

Description

NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance Manager and NGINX API Connectivity Manager.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected (3)

3 products
Nginx Api Connectivity Manager
Nginx Instance Manager
Nginx Security Monitoring
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
From 1.0.0 to 1.5.0
From 2.0.0 to 2.9.0
From 1.0.0 to 1.3.0

References (4)

Source: f5sirt@f5.com
Vendor Advisory
Source: f5sirt@f5.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.