CVE-2020-5909: Medium severity f5 nginx controller api management vulnerability
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5909?
CVE-2020-5909 has been classified as medium severity due to the potential risks associated with a TLS certificate validation bypass.
How does CVE-2020-5909 affect F5 Nginx Controller users?
CVE-2020-5909 affects users by allowing the possibility of unverified server connections leading to potential man-in-the-middle attacks.
How do I fix CVE-2020-5909?
To fix CVE-2020-5909, update the F5 Nginx Controller to a version higher than 3.5.0, 2.9.0, or 1.0.1.
Is CVE-2020-5909 exploitable by remote attackers?
Yes, CVE-2020-5909 can be exploited by remote attackers due to the server TLS certificate verification issue.
What versions of F5 Nginx Controller are vulnerable to CVE-2020-5909?
F5 Nginx Controller versions 3.0.0 to 3.5.0, 2.0.0 to 2.9.0, and 1.0.1 are vulnerable to CVE-2020-5909.