Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-28724


NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensitive files on NGINX Instance Manager and NGINX API Connectivity Manager.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.


Published

2023-05-03T15:15:13.020

Last Modified

2025-04-10T20:32:16.720

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.1 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-276
  • Type: Primary
    CWE-276

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application f5 nginx_api_connectivity_manager < 1.5.0 Yes
Application f5 nginx_instance_manager < 2.9.0 Yes
Application f5 nginx_security_monitoring < 1.3.0 Yes

References