CVE-2024-7634 MEDIUM

CVE-2024-7634: NGINX Agent Vulnerability

Vendor F5
Product NGINX Agent
Weakness CWE-22 · Path traversal
Published August 22, 2024
Last update August 22, 2024

CVSS base score

4.9/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

What the vulnerability does

Description

NGINX Agent's "config_dirs" restriction feature allows a highly privileged attacker to gain the ability to write/overwrite files outside of the designated secure directory.

Key dates

Disclosure timeline

August 22, 2024 CVE published
August 22, 2024 Record updated