F5 Vulnerabilities and Affected Products
Vulnerabilities associated with nginx.
Products
Clear product- BIG-IP257 vulnerabilities
- NGINX Plus31 vulnerabilities
- NGINX Open Source29 vulnerabilities
- BIG-IP Next CNF26 vulnerabilities
- BIG-IP Next SPK23 vulnerabilities
- BIG-IQ19 vulnerabilities
- BIG-IP Next for Kubernetes13 vulnerabilities
- BIG-IP APM12 vulnerabilities
- F5OS - Appliance12 vulnerabilities
- BIG-IP Edge Client11 vulnerabilities
- F5OS - Chassis10 vulnerabilities
- BIG-IP Next Central Manager9 vulnerabilities
- BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator)8 vulnerabilities
- BIG-IQ Centralized Management7 vulnerabilities
- big-ip_next_central_manager6 vulnerabilities
- nginx6 vulnerabilities
- NGINX Ingress Controller5 vulnerabilities
- NGINX Instance Manager5 vulnerabilities
- nginx_plus5 vulnerabilities
- BIG-IP Guided Configuration (GC)4 vulnerabilities
- BIG-IP Next4 vulnerabilities
- F5OS-A4 vulnerabilities
- BIG-IP Advanced WAF & ASM3 vulnerabilities
- BIG-IP AFM3 vulnerabilities
- BIG-IP APM Clients3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-34161MEDIUM | NGINX HTTP/3 QUIC vulnerabilityWhen NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory. CWE-416May 29, 2024 | CVSS5.3v3.1 | EPSS0.867% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-35200MEDIUM | NGINX HTTP/3 QUIC vulnerabilityWhen NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate. CWE-476May 29, 2024 | CVSS5.3v3.1 | EPSS0.934% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-32760MEDIUM | NGINX HTTP/3 QUIC vulnerabilityWhen NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause or other potential impact. CWE-787May 29, 2024 | CVSS6.5v3.1 | EPSS0.864% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-31079MEDIUM | NGINX HTTP/3 QUIC vulnerabilityWhen NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically timed during the connection draining process, which the attacker has no visibility and limited influence over. | CVSS4.8v3.1 | EPSS0.888% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-41742HIGH | NGINX ngx_http_mp4_module vulnerability CVE-2022-41742NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted audio or video file. The issue affects only NGINX products that are built with the module ngx_http_mp4_module, when the mp4 directi… CWE-787Oct 19, 2022 | CVSS7.1v3.1 | EPSS1.12% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-41741HIGH | NGINX ngx_http_mp4_module vulnerability CVE-2022-41741NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its termination or potential other impact using a specially crafted audio or video file. The issue affects only NGINX products that are built with the ngx_http_mp4_module, when the mp4 directive is us… CWE-787Oct 19, 2022 | CVSS7.0v3.1 | EPSS0.777% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |