Vulnerabilities > F5 > Nginx Controller > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-06-01 CVE-2021-23020 Use of Insufficiently Random Values vulnerability in F5 Nginx Controller
The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and hashing algorithm which could lead to predictable keys.
local
low complexity
f5 CWE-330
5.5
2021-06-01 CVE-2021-23021 Incorrect Permission Assignment for Critical Resource vulnerability in F5 Nginx Controller
The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with current permission bits set to 644.
local
low complexity
f5 CWE-732
5.5
2020-07-02 CVE-2020-5909 Improper Certificate Validation vulnerability in F5 Nginx Controller
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.
network
low complexity
f5 CWE-295
5.4
2020-04-23 CVE-2020-5866 Information Exposure vulnerability in F5 Nginx Controller
In versions of NGINX Controller prior to 3.3.0, the helper.sh script, which is used optionally in NGINX Controller to change settings, uses sensitive items as command-line arguments.
local
low complexity
f5 CWE-200
5.5
2020-04-23 CVE-2020-5865 Cleartext Transmission of Sensitive Information vulnerability in multiple products
In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, making the communicated data vulnerable to interception via man-in-the-middle (MiTM) attacks.
network
high complexity
f5 netapp CWE-319
4.8