Vulnerabilities
Vulnerable Software
F5:  >> Nginx Controller  >> 3.2.0  Security Vulnerabilities
On versions 3.0.0-3.3.0, the NGINX Controller webserver does not invalidate the server-side session token after users log out.
CVSS Score
8.1
EPSS Score
0.004
Published
2020-05-07
On NGINX Controller versions 3.1.0-3.3.0, AVRD uses world-readable and world-writable permissions on its socket, which allows processes or users on the local system to write arbitrary data into the socket. A local system attacker can make AVRD segmentation fault (SIGSEGV) by writing malformed messages to the socket.
CVSS Score
7.8
EPSS Score
0.001
Published
2020-05-07
In versions prior to 3.3.0, the NGINX Controller Agent installer script 'install.sh' uses HTTP instead of HTTPS to check and install packages
CVSS Score
8.1
EPSS Score
0.001
Published
2020-04-23
In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, making the communicated data vulnerable to interception via man-in-the-middle (MiTM) attacks.
CVSS Score
4.8
EPSS Score
0.001
Published
2020-04-23
In versions of NGINX Controller prior to 3.3.0, the helper.sh script, which is used optionally in NGINX Controller to change settings, uses sensitive items as command-line arguments.
CVSS Score
5.5
EPSS Score
0.001
Published
2020-04-23
In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS verification by default.
CVSS Score
7.4
EPSS Score
0.004
Published
2020-04-23


Contact Us

Shodan ® - All rights reserved