CVE Vulnerabilities

CVE-2021-23019

Insufficiently Protected Credentials

Published: Jun 01, 2021 | Modified: Aug 30, 2022
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file that is included in the NGINX support package.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Nginx_controller F5 2.0.0 (including) 2.9.0 (including)
Nginx_controller F5 3.0.0 (including) 3.15.0 (excluding)

Potential Mitigations

References