Vulnerability Description
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| F5 | Nginx Controller | >= 2.0.0, <= 2.9.0 |
Related Weaknesses (CWE)
References
- https://support.f5.com/csp/article/K59209532Vendor Advisory
- https://support.f5.com/csp/article/K59209532Vendor Advisory
FAQ
What is CVE-2020-5910?
CVE-2020-5910 is a vulnerability with a CVSS score of 7.5 (HIGH). In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any succes...
How severe is CVE-2020-5910?
CVE-2020-5910 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-5910?
Check the references section above for vendor advisories and patch information. Affected products include: F5 Nginx Controller.