threat
engine
.sh
Back
·
··:··
Home
/
Product
/
f5 nginx controller
Product
f5 nginx controller
18 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2021-23021
>= 3.0.0 and < 3.7.0
The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with current per
5.5
MEDIUM
CVE-2021-23020
>= 3.0.0 and < 3.10.0
The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and hashing algorithm which could lead t
5.5
MEDIUM
CVE-2021-23019
>= 2.0.0 and <= 2.9.0
The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file that is
7.8
HIGH
CVE-2021-23018
>= 3.0.0 and <= 3.4.0
Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are using cleart
7.4
HIGH
CVE-2020-27730
>= 2.0.0 and <= 2.9.0
In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling system utilit
9.8
CRITICAL
CVE-2020-5911
>= 2.0.0 and <= 2.9.0
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an
7.3
HIGH
CVE-2020-5910
>= 2.0.0 and <= 2.9.0
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGI
7.5
HIGH
CVE-2020-5909
>= 2.0.0 and <= 2.9.0
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to f
5.4
MEDIUM
CVE-2020-5901
>= 3.3.0 and <= 3.4.0
In NGINX Controller 3.3.0-3.4.0, undisclosed API endpoints may allow for a reflected Cross Site Scripting (XSS) attack. If the vic
9.6
CRITICAL
CVE-2020-5899
>= 3.0.0 and <= 3.4.0
In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in p
7.8
HIGH
CVE-2020-5900
>= 2.0.0 and <= 2.9.0
In versions 3.0.0-3.4.0, 2.0.0-2.9.0, and 1.0.1, there is insufficient cross-site request forgery (CSRF) protections for the NGINX
8.8
HIGH
CVE-2020-5895
>= 3.1.0 and < 3.4.0
On NGINX Controller versions 3.1.0-3.3.0, AVRD uses world-readable and world-writable permissions on its socket, which allows proc
7.8
HIGH
CVE-2020-5894
>= 3.0.0 and <= 3.3.0
On versions 3.0.0-3.3.0, the NGINX Controller webserver does not invalidate the server-side session token after users log out.
8.1
HIGH
CVE-2020-5867
>= 2.0.0 and <= 2.9.0
In versions prior to 3.3.0, the NGINX Controller Agent installer script 'install.sh' uses HTTP instead of HTTPS to check and insta
8.1
HIGH
CVE-2020-5866
>= 2.0.0 and <= 2.9.0
In versions of NGINX Controller prior to 3.3.0, the helper.sh script, which is used optionally in NGINX Controller to change setti
5.5
MEDIUM
CVE-2020-5865
>= 2.0.0 and <= 2.9.0
In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted c
4.8
MEDIUM
CVE-2020-5864
>= 2.0.0 and <= 2.9.0
In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS verificat
7.4
HIGH
CVE-2020-5863
>= 2.0.0 and <= 2.9.0
In NGINX Controller versions prior to 3.2.0, an unauthenticated attacker with network access to the Controller API can create unpr
8.6
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin