8.1

CVE-2023-28656

NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment.  

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NetappCloud Backup Version-
F5Nginx Api Connectivity Manager Version >= 1.0.0 < 1.5.0
F5Nginx Instance Manager Version >= 2.0.0 < 2.9.0
F5Nginx Security Monitoring Version >= 1.0.0 < 1.3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.427
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
f5sirt@f5.com 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CWE-639 Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.