CVE-2023-28656: NGINX Management Suite vulnerability
NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Other sources
NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment.( CVE-2023-28656)
— F5
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-28656?
CVE-2023-28656 is a vulnerability in NGINX Management Suite that allows an authenticated attacker to gain access to configuration objects outside of their assigned environment.
What is the severity of CVE-2023-28656?
CVE-2023-28656 has a severity score of 8.1, which is considered high.
Which software versions are affected by CVE-2023-28656?
The affected software versions for CVE-2023-28656 are F5 Nginx Api Connectivity Manager (versions 1.0.0 to 1.5.0), F5 Nginx Instance Manager (versions 2.0.0 to 2.9.0), and F5 Nginx Security Monitoring (versions 1.0.0 to 1.3.0).
How can an attacker exploit CVE-2023-28656?
An attacker can exploit CVE-2023-28656 by gaining authenticated access to NGINX Management Suite and then accessing configuration objects outside of their assigned environment.
Is there a fix available for CVE-2023-28656?
Yes, F5 has released patches and it is recommended to update to the latest version of the affected software to mitigate the vulnerability.