8.6

CVE-2020-5863

In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unprivileged user accounts. The user which is created is only able to upload a new license to the system but cannot view or modify any other components of the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
F5 ≫ Nginx Controller Version >= 2.0.0 <= 2.9.0
F5 ≫ Nginx Controller Version >= 3.0.0 < 3.2.0
F5 ≫ Nginx Controller Version 1.0.1
Netapp ≫ Cloud Backup Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.15% 0.64
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.6 3.9 4.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://security.netapp.com/advisory/ntap-20200430-0005/
Third Party Advisory
https://support.f5.com/csp/article/K14631834
Vendor Advisory