CVE-2023-28656

NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy:-:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_security_monitoring:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_api_connectivity_manager:*:*:*:*:*:*:*:*

History

19 May 2025, 14:45

Type Values Removed Values Added
References () https://security.netapp.com/advisory/ntap-20230609-0006/ - () https://security.netapp.com/advisory/ntap-20230609-0006/ - Third Party Advisory
CPE cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
First Time Netapp cloud Backup
Netapp
Netapp ontap Select Deploy

13 Feb 2025, 17:16

Type Values Removed Values Added
References (MISC) https://security.netapp.com/advisory/ntap-20230609-0006/ - () https://security.netapp.com/advisory/ntap-20230609-0006/ -
References (MISC) https://my.f5.com/manage/s/article/K000133417 - Vendor Advisory () https://my.f5.com/manage/s/article/K000133417 - Vendor Advisory
Summary NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
CVSS v2 : unknown
v3 : 8.1
v2 : unknown
v3 : unknown

09 Jun 2023, 08:15

Type Values Removed Values Added
References
  • (MISC) https://security.netapp.com/advisory/ntap-20230609-0006/ -

10 May 2023, 18:56

Type Values Removed Values Added
First Time F5
F5 nginx Api Connectivity Manager
F5 nginx Instance Manager
F5 nginx Security Monitoring
CPE cpe:2.3:a:f5:nginx_instance_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_security_monitoring:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx_api_connectivity_manager:*:*:*:*:*:*:*:*
References (MISC) https://my.f5.com/manage/s/article/K000133417 - (MISC) https://my.f5.com/manage/s/article/K000133417 - Vendor Advisory

03 May 2023, 15:23

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-03 15:15

Updated : 2025-05-19 14:45


NVD link : CVE-2023-28656

Mitre link : CVE-2023-28656


JSON object : View

Products Affected

f5

  • nginx_api_connectivity_manager
  • nginx_instance_manager
  • nginx_security_monitoring

netapp

  • ontap_select_deploy
  • cloud_backup
CWE
CWE-639

Authorization Bypass Through User-Controlled Key