CVE-2020-5867

EUVD-2020-27021
In versions prior to 3.3.0, the NGINX Controller Agent installer script 'install.sh' uses HTTP instead of HTTPS to check and install packages
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
Affected Products (NVD)
VendorProductVersion
f5nginx_controller
2.0.0 ≤
𝑥
≤ 2.9.0
f5nginx_controller
3.0.0 ≤
𝑥
< 3.3.0
f5nginx_controller
1.0.1
netappcloud_backup
-
𝑥
= Vulnerable software versions