#VU27301 Man-in-the-Middle (MitM) attack in NGINX Controller - CVE-2020-5865
Published: April 24, 2020
NGINX Controller
F5 Networks
Description
The vulnerability allows a remote attacker to perform a man-in-the-middle (MitM) attack.
The vulnerability exists due to the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels. A remote attacker can perform a MitM attack, intercept communicated data and modify user entered data or run arbitrary SQL commands against the database server.