Vulnerability Details CVE-2023-28656
NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.0%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2023-28656
-
cpe:2.3:a:f5:nginx_api_connectivity_manager:1.0.0
-
cpe:2.3:a:f5:nginx_api_connectivity_manager:1.4.1
-
cpe:2.3:a:f5:nginx_instance_manager:2.0.0
-
cpe:2.3:a:f5:nginx_instance_manager:2.0.1
-
cpe:2.3:a:f5:nginx_instance_manager:2.1.0
-
cpe:2.3:a:f5:nginx_instance_manager:2.2.0
-
cpe:2.3:a:f5:nginx_instance_manager:2.3.0
-
cpe:2.3:a:f5:nginx_instance_manager:2.3.1
-
cpe:2.3:a:f5:nginx_instance_manager:2.4.0
-
cpe:2.3:a:f5:nginx_instance_manager:2.5.0
-
cpe:2.3:a:f5:nginx_instance_manager:2.5.1
-
cpe:2.3:a:f5:nginx_instance_manager:2.6.0
-
cpe:2.3:a:f5:nginx_instance_manager:2.7.0
-
cpe:2.3:a:f5:nginx_instance_manager:2.8.0
-
cpe:2.3:a:f5:nginx_security_monitoring:1.0.0
-
cpe:2.3:a:f5:nginx_security_monitoring:1.2.0
-
cpe:2.3:a:netapp:cloud_backup:-
-
cpe:2.3:a:netapp:ontap_select_deploy:-