CVE-2023-28724: High severity ptc thingworx industrial connectivity vulnerability
NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance Manager and NGINX API Connectivity Manager.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-28724?
CVE-2023-28724 is a vulnerability in the NGINX Management Suite that allows an authenticated attacker to modify sensitive files on NGINX Instance Manager and NGINX API Connectivity Manager.
What is the severity of CVE-2023-28724?
CVE-2023-28724 has a severity level of 7.1, which is considered high.
Which software versions are affected by CVE-2023-28724?
The affected software versions are F5 Nginx Api Connectivity Manager 1.0.0 to 1.5.0 and F5 Nginx Instance Manager 2.0.0 to 2.9.0.
How can an attacker exploit CVE-2023-28724?
An authenticated attacker can exploit CVE-2023-28724 by modifying sensitive files on NGINX Instance Manager and NGINX API Connectivity Manager.
Is there a fix for CVE-2023-28724?
Yes, F5 Networks has provided mitigation steps for CVE-2023-28724 in their advisory. Please refer to the official F5 Networks advisory for more information.