F5-K000160367: Low severity F5 NGINX Plus vulnerability
NGINX Plus and NGINX Open Source have a vulnerability in the ngxmailsmtpmodule module due to the improper handling of CRLF sequences in DNS responses. This allows an attacker-controlled DNS server to inject arbitrary headers into SMTP upstream requests, leading to potential request manipulation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000160367?
The severity of F5-K000160367 is considered high due to potential request manipulation risks.
How do I fix F5-K000160367?
To fix F5-K000160367, upgrade to NGINX Plus version 36 or NGINX Open Source version 1.29.7 or higher.
Which products are affected by F5-K000160367?
F5-K000160367 affects NGINX Plus version 32 and NGINX Open Source versions from 1.0.0 to 1.29.6 and from 0.6.27 to 0.9.7.
What kind of attacks does F5-K000160367 open up to?
F5-K000160367 can allow attackers to inject arbitrary headers into SMTP requests through manipulated DNS responses.
How can I verify if I am vulnerable to F5-K000160367?
You can verify vulnerability to F5-K000160367 by checking your NGINX Plus or NGINX Open Source version against the specified affected versions.