CVE-2020-5910: High severity f5 nginx controller api management vulnerability
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5910?
CVE-2020-5910 has a high severity rating due to its lack of authentication allowing unauthorized access to messaging services.
How do I fix CVE-2020-5910?
To fix CVE-2020-5910, upgrade to a version of NGINX Controller that is outside the affected range, specifically to versions beyond 3.5.0 or 2.9.0.
What systems are affected by CVE-2020-5910?
CVE-2020-5910 affects NGINX Controller versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1.
What are the risks associated with CVE-2020-5910?
The risks associated with CVE-2020-5910 include potential unauthorized access and control over messaging services without any authentication.
Can CVE-2020-5910 lead to data breaches?
Yes, CVE-2020-5910 can potentially lead to data breaches due to the unauthorized access it enables.