CVE-2023-28724
03.05.2023, 15:15
NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance Manager and NGINX API Connectivity Manager. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.Enginsight
Vendor | Product | Version |
---|---|---|
f5 | nginx_api_connectivity_manager | 1.0.0 ≤ 𝑥 < 1.5.0 |
f5 | nginx_instance_manager | 2.0.0 ≤ 𝑥 < 2.9.0 |
f5 | nginx_security_monitoring | 1.0.0 ≤ 𝑥 < 1.3.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration