CVE-2020-5865

MEDIUM

NGINX Controller <3.3.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, making the communicated data vulnerable to interception via man-in-the-middle (MiTM) attacks.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://support.f5.com/csp/article/K21009022
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20200430-0005/

Scores

CVSS v3 4.8
EPSS 0.0012
EPSS Percentile 30.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-319
Status published
Products (3)
f5/nginx_controller 1.0.1
f5/nginx_controller 2.0.0 - 2.9.0
netapp/cloud_backup
Published Apr 23, 2020
Tracked Since Feb 18, 2026