When NGINX Plus or NGINX Open Source are configured to use the HTTP/3 QUIC module, an attacker may be able to spoof their source IP address allowing for bypass of authorization or bypass of rate limiting. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.3.0, <= 4.7.0CPE matchmatch criteria | cpe:2.3:a:f5:dos:*:*:*:*:*:nginx:*:* | ||
4.8.0CPE matchmatch criteria | cpe:2.3:a:f5:dos:4.8.0:*:*:*:*:nginx:*:* | ||
>= 1.3.0, <= 1.6.2CPE matchmatch criteria | cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:* | ||
>= 2.0.0, <= 2.6.0CPE matchmatch criteria | cpe:2.3:a:f5:nginx_gateway_fabric:*:*:*:*:*:*:*:* | ||
>= 3.5.0, <= 3.7.2CPE matchmatch criteria | cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.