F5 Vulnerabilities and Affected Products
Vulnerabilities associated with nginx_plus.
Products
Clear product- BIG-IP257 vulnerabilities
- NGINX Plus31 vulnerabilities
- NGINX Open Source29 vulnerabilities
- BIG-IP Next CNF26 vulnerabilities
- BIG-IP Next SPK23 vulnerabilities
- BIG-IQ19 vulnerabilities
- BIG-IP Next for Kubernetes13 vulnerabilities
- BIG-IP APM12 vulnerabilities
- F5OS - Appliance12 vulnerabilities
- BIG-IP Edge Client11 vulnerabilities
- F5OS - Chassis10 vulnerabilities
- BIG-IP Next Central Manager9 vulnerabilities
- BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator)8 vulnerabilities
- BIG-IQ Centralized Management7 vulnerabilities
- big-ip_next_central_manager6 vulnerabilities
- nginx6 vulnerabilities
- NGINX Ingress Controller5 vulnerabilities
- NGINX Instance Manager5 vulnerabilities
- nginx_plus5 vulnerabilities
- BIG-IP Guided Configuration (GC)4 vulnerabilities
- BIG-IP Next4 vulnerabilities
- F5OS-A4 vulnerabilities
- BIG-IP Advanced WAF & ASM3 vulnerabilities
- BIG-IP AFM3 vulnerabilities
- BIG-IP APM Clients3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-39792HIGH | NGINX Plus MQTT vulnerabilityWhen the NGINX Plus is configured to use the MQTT pre-read module, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS8.7v4.0 | EPSS0.628% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-34161MEDIUM | NGINX HTTP/3 QUIC vulnerabilityWhen NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory. CWE-416May 29, 2024 | CVSS5.3v3.1 | EPSS0.867% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-35200MEDIUM | NGINX HTTP/3 QUIC vulnerabilityWhen NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate. CWE-476May 29, 2024 | CVSS5.3v3.1 | EPSS0.934% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-32760MEDIUM | NGINX HTTP/3 QUIC vulnerabilityWhen NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can cause NGINX worker processes to terminate or cause or other potential impact. CWE-787May 29, 2024 | CVSS6.5v3.1 | EPSS0.864% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-31079MEDIUM | NGINX HTTP/3 QUIC vulnerabilityWhen NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically timed during the connection draining process, which the attacker has no visibility and limited influence over. | CVSS4.8v3.1 | EPSS0.888% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |